CVE-2011-5256: XSS
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5256?
CVE-2011-5256 has a medium severity rating due to its cross-site scripting nature.
How do I fix CVE-2011-5256?
To fix CVE-2011-5256, update LimeSurvey to version 1.91+ Build 11379-20111116 or later.
Which versions of LimeSurvey are affected by CVE-2011-5256?
CVE-2011-5256 affects LimeSurvey versions prior to 1.91+, including versions like 1.80+, 1.72, and 1.85.
What is the exploit method for CVE-2011-5256?
CVE-2011-5256 allows attackers to exploit the vulnerability through injecting arbitrary web scripts into tooltips.
What are the potential impacts of CVE-2011-5256?
The potential impacts of CVE-2011-5256 include unauthorized access to user data and the ability to execute scripts in the context of other users.