CVE-2024-24506

MEDIUM

Lime Survey CE <v.5.3.32+220817 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-24506. PoCs published by Subhankar Singh.

AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in LimeSurvey Community Edition Version 5.3.32+220817. The vulnerability allows an attacker to inject malicious JavaScript payloads into the 'Administrator email address' field, which are then executed when the page is saved or reloaded.

Description

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.

Exploits (1)

exploitdb WRITEUP
by Subhankar Singh · textwebappsphp
https://www.exploit-db.com/exploits/51926

This is a writeup describing a stored XSS vulnerability in LimeSurvey Community Edition Version 5.3.32+220817. The vulnerability allows an attacker to inject malicious JavaScript payloads into the 'Administrator email address' field, which are then executed when the page is saved or reloaded.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: LimeSurvey Community Edition Version 5.3.32+220817
Auth required
Prerequisites: Access to LimeSurvey admin panel
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0037
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
limesurvey/limesurvey 5.3.32 220817
Published Apr 03, 2024
Tracked Since Feb 18, 2026