CVE-2014-5018: XSS
Incomplete blacklist vulnerability in the autoEscape function in commonhelper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5018?
CVE-2014-5018 has been classified as a medium severity vulnerability due to its ability to facilitate cross-site scripting attacks.
How do I fix CVE-2014-5018?
To fix CVE-2014-5018, you should update LimeSurvey to the latest version that addresses this vulnerability.
What kind of attacks can be executed through CVE-2014-5018?
CVE-2014-5018 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GBK charset in the loadname parameter.
Which versions of LimeSurvey are affected by CVE-2014-5018?
LimeSurvey versions 2.05+ Build 140618 and earlier are affected by CVE-2014-5018.
What is the impact of exploiting CVE-2014-5018?
Exploiting CVE-2014-5018 can lead to unauthorized script execution in the user's browser, potentially compromising user data and session information.