CVE-2019-16180

MEDIUM

Limesurvey <3.17.14 - Info Disclosure

Title source: llm
STIX 2.1

Description

Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (1)
limesurvey/limesurvey < 3.17.14
Published Sep 09, 2019
Tracked Since Feb 18, 2026