CVE-2008-2571
Limesurvey < 1.70 - XSS
Title source: ruleDescription
Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.
References (5)
Scores
EPSS
0.0036
EPSS Percentile
57.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (3)
limesurvey/limesurvey
< 1.70
limesurvey/limesurvey
limesurvey/limesurvey
Timeline
Published
Jun 06, 2008
Tracked Since
Feb 18, 2026