CVE-2019-16173
MEDIUMLimeSurvey < 3.17.14 - Reflected Cross-Site Scripting in Survey_Common_Action.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-16173. PoCs published by SEC Consult.
AI-analyzed exploit summary The document describes stored and reflected XSS vulnerabilities in LimeSurvey versions <= 3.17.13, with proof-of-concept examples demonstrating how JavaScript payloads can be executed in the context of a victim's session.
Description
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
Exploits (1)
The document describes stored and reflected XSS vulnerabilities in LimeSurvey versions <= 3.17.13, with proof-of-concept examples demonstrating how JavaScript payloads can be executed in the context of a victim's session.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N