CVE-2014-5017: SQL Injection
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipantsjson, related to a search parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5017?
CVE-2014-5017 is considered to have high severity due to the potential for arbitrary SQL command execution.
How do I fix CVE-2014-5017?
To fix CVE-2014-5017, update LimeSurvey to a version later than 2.05 Build 140618 that addresses this vulnerability.
What components are affected by CVE-2014-5017?
CVE-2014-5017 affects the CPDB component in the LimeSurvey application.
Is remote exploitation possible with CVE-2014-5017?
Yes, CVE-2014-5017 allows remote attackers to exploit the vulnerability through the sidx parameter.
What type of vulnerability is CVE-2014-5017 classified as?
CVE-2014-5017 is classified as an SQL injection vulnerability.