CVE-2008-2571

Limesurvey < 1.70 - XSS

Title source: rule

Description

Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.

Scores

EPSS 0.0036
EPSS Percentile 57.6%

Classification

CWE
CWE-79
Status draft

Affected Products (3)

limesurvey/limesurvey < 1.70
limesurvey/limesurvey
limesurvey/limesurvey

Timeline

Published Jun 06, 2008
Tracked Since Feb 18, 2026