CVE-2008-2571: XSS
Published Jun 6, 2008
·Updated
Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.
Affected Software
3 affected components
Limesurvey LimeSurvey<=1.70
Limesurvey LimeSurvey=1.49
Limesurvey LimeSurvey=1.52
Remediation
Patch Available
Event History
Jun 6, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2571?
CVE-2008-2571 is considered a moderate severity vulnerability due to its impact on administrative privileges.
2
How do I fix CVE-2008-2571?
To fix CVE-2008-2571, upgrade LimeSurvey to version 1.71 or later.
3
What types of attacks are possible with CVE-2008-2571?
CVE-2008-2571 allows attackers to execute cross-site request forgery attacks that manipulate quotas.
4
Which versions of LimeSurvey are affected by CVE-2008-2571?
CVE-2008-2571 affects all LimeSurvey versions prior to 1.71, including versions 1.49 and 1.52.
5
Who is primarily targeted by CVE-2008-2571?
CVE-2008-2571 primarily targets administrators of LimeSurvey installations.