CVE-2018-1000514: CSRF
Published Jun 26, 2018
·Updated
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Boxes that can result in CSRF admins to delete boxes. This vulnerability appears to have been fixed in 3.6.x.
Affected Software
1 affected component
Limesurvey LimeSurvey=3.0.0-beta.3\+17110
Remediation
Event History
Jun 26, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for LimeSurvey?
The vulnerability ID for LimeSurvey is CVE-2018-1000514.
2
What is the severity of CVE-2018-1000514?
The severity of CVE-2018-1000514 is medium with a severity value of 4.3.
3
What is affected by CVE-2018-1000514?
LimeSurvey version 3.0.0-beta.3+17110 is affected by CVE-2018-1000514.
4
How can the vulnerability be exploited?
The vulnerability can be exploited through Cross-Site Request Forgery (CSRF) attacks.
5
Has CVE-2018-1000514 been fixed?
Yes, CVE-2018-1000514 has been fixed in LimeSurvey version 3.6.x.