First published: Sun Jun 28 2015(Updated: )
SQL injection vulnerability in the insert function in application/controllers/admin/dataentry.php in LimeSurvey 2.06+ allows remote authenticated users to execute arbitrary SQL commands via the closedate parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LimeSurvey | =2.06\+ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5078 is classified as having a medium severity due to its potential for SQL injection exploits.
To fix CVE-2015-5078, upgrade to LimeSurvey version 2.06+ or apply appropriate input validation and sanitization methods.
Remote authenticated users of LimeSurvey version 2.06+ are affected by CVE-2015-5078.
CVE-2015-5078 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
The closedate parameter in the insert function of LimeSurvey is involved in CVE-2015-5078.