CVE-2015-4628: SQL Injection
Published Jun 18, 2015
·Updated
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
Affected Software
1 affected component
Limesurvey LimeSurvey<=2.06\+
Event History
Jun 18, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4628?
CVE-2015-4628 has a high severity due to the potential for remote authenticated attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2015-4628?
To fix CVE-2015-4628, upgrade LimeSurvey to version 2.06+ Build 150618 or later.
3
Who is affected by CVE-2015-4628?
CVE-2015-4628 affects LimeSurvey versions prior to 2.06+ Build 150618.
4
What can attackers gain by exploiting CVE-2015-4628?
By exploiting CVE-2015-4628, attackers can gain unauthorized access to and manipulate the database.
5
What is the nature of the vulnerability in CVE-2015-4628?
CVE-2015-4628 is a SQL injection vulnerability that allows the execution of arbitrary SQL commands.