vendor:
LimeSurvey
by:
Y1LD1R1M
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: LimeSurvey
Affected Version From: 5.2.x
Affected Version To: 5.2.2004
Patch Exists: YES
Related CWE:
CPE: a:limesurvey:limesurvey
Platforms Tested: Kali Linux 2021.3
2021
LimeSurvey 5.2.4 – Remote Code Execution (RCE) (Authenticated)
LimeSurvey is vulnerable to Remote Code Execution (RCE) when an authenticated user sends a maliciously crafted request to the application. An attacker can exploit this vulnerability to execute arbitrary code on the server.
Mitigation:
Update to the latest version of LimeSurvey and apply the latest security patches.