CVE-2018-10228: XSS
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changescp parameter to the index.php/admin/themes/sa/templatesavechanges URI.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10228?
CVE-2018-10228 is a cross-site scripting (XSS) vulnerability in LimeSurvey 3.6.2+180406.
How does CVE-2018-10228 affect LimeSurvey?
CVE-2018-10228 allows remote attackers to inject arbitrary web script or HTML through the changes_cp parameter in the /application/controller/admin/theme.php file.
What is the severity of CVE-2018-10228?
The severity of CVE-2018-10228 is medium with a CVSS score of 6.1.
How can the XSS vulnerability in LimeSurvey be exploited?
The XSS vulnerability in LimeSurvey can be exploited by sending malicious web script or HTML code through the changes_cp parameter in the /application/controller/admin/theme.php file.
Is there a fix for CVE-2018-10228?
Yes, LimeSurvey version 3.6.3 or later addresses the XSS vulnerability CVE-2018-10228.