First published: Thu Jun 18 2015(Updated: )
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
LimeSurvey | <=2.06\+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4628 has a high severity due to the potential for remote authenticated attackers to execute arbitrary SQL commands.
To fix CVE-2015-4628, upgrade LimeSurvey to version 2.06+ Build 150618 or later.
CVE-2015-4628 affects LimeSurvey versions prior to 2.06+ Build 150618.
By exploiting CVE-2015-4628, attackers can gain unauthorized access to and manipulate the database.
CVE-2015-4628 is a SQL injection vulnerability that allows the execution of arbitrary SQL commands.