CVE-2012-4995: XSS
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the fullname parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4995?
CVE-2012-4995 is considered a medium-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2012-4995?
To fix CVE-2012-4995, upgrade LimeSurvey to version 1.91+ Build 120224 or later.
What systems are affected by CVE-2012-4995?
CVE-2012-4995 affects multiple versions of LimeSurvey, including versions prior to 1.91+ and specific versions like 1.50, 1.52, and 1.87+.
Can CVE-2012-4995 be exploited remotely?
Yes, CVE-2012-4995 can be exploited remotely by attackers through the full_name parameter.
What is the potential impact of CVE-2012-4995?
The potential impact of CVE-2012-4995 includes unauthorized injection of arbitrary web scripts or HTML, which can lead to session hijacking or web page manipulation.