Markus Flür

2 exploits Active since Sep 2018
CVE-2018-16397 WRITEUP MEDIUM WRITEUP
Limesurvey < 3.14.7 - Unrestricted File Upload
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
CVSS 4.9
CVE-2019-15640 WRITEUP HIGH WRITEUP
Limesurvey < 3.17.10 - Improper Input Validation
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
CVSS 7.5