CVE-2012-4994: SQL Injection
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4994?
CVE-2012-4994 is typically classified as a medium severity vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
How do I fix CVE-2012-4994?
To fix CVE-2012-4994, you should upgrade to LimeSurvey version 1.91+ Build 120224 or later, which includes a patch against this vulnerability.
Who is affected by CVE-2012-4994?
CVE-2012-4994 affects remote authenticated users of LimeSurvey versions prior to 1.91+ Build 120224.
What type of vulnerability is CVE-2012-4994?
CVE-2012-4994 is an SQL injection vulnerability that allows execution of arbitrary SQL commands via a vulnerable parameter.
What could an attacker achieve by exploiting CVE-2012-4994?
An attacker exploiting CVE-2012-4994 could potentially gain unauthorized access to the database, manipulate data, or execute administrative functions.