CVE-2019-16172
MEDIUMLimeSurvey < 3.17.14 - Stored Cross-Site Scripting via Survey Group Title
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-16172. PoCs published by TrixSec.
AI-analyzed exploit summary The repository contains a Python script that scans for CVE-2019-16172, a stored XSS vulnerability in LimeSurvey versions prior to 3.17. It sends a crafted payload to the /admin/survey/group/create endpoint and checks the response to determine vulnerability.
Description
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
Exploits (2)
The repository contains a Python script that scans for CVE-2019-16172, a stored XSS vulnerability in LimeSurvey versions prior to 3.17. It sends a crafted payload to the /admin/survey/group/create endpoint and checks the response to determine vulnerability.
This advisory details stored and reflected XSS vulnerabilities in LimeSurvey <= 3.17.13, providing technical descriptions, proof-of-concept payloads, and patch references. It includes specific attack vectors and affected parameters.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N