Description
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
References (2)
Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R40
Scores
CVSS v3
8.8
EPSS
0.0113
EPSS Percentile
78.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (1)
limesurvey/limesurvey
< 3.17.14
Published
Sep 09, 2019
Tracked Since
Feb 18, 2026