CVE-2018-1000053

HIGH

LimeSurvey 3.0.0-beta.3+17110 - CSRF

Title source: llm
STIX 2.1

Description

LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear to be exploitable via Simple HTML markup can be used to send a GET request to the affected endpoint.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0013
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
limesurvey/limesurvey 3.0.0 beta3
Published Feb 09, 2018
Tracked Since Feb 18, 2026