CVE-2018-16397: Malicious File Upload
Published Sep 3, 2018
·Updated
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
Affected Software
1 affected component
Limesurvey LimeSurvey<3.14.7
Event History
Sep 3, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-16397.
2
What is the severity of CVE-2018-16397?
The severity of CVE-2018-16397 is medium.
3
How can an admin user exploit CVE-2018-16397?
An admin user can exploit CVE-2018-16397 by leveraging a file upload question to read an arbitrary file.
4
Which version of LimeSurvey is affected by CVE-2018-16397?
LimeSurvey versions up to, but not including, 3.14.7 are affected by CVE-2018-16397.
5
Where can I find more information about CVE-2018-16397?
You can find more information about CVE-2018-16397 at the following link: [github.com/LimeSurvey/LimeSurvey/blob/3be9b41e76826b57f5860d18d93b23f47d59d2e4/docs/release_notes.txt#L51](github.com/LimeSurvey/LimeSurvey/blob/3be9b41e76826b57f5860d18d93b23f47d59d2e4/docs/release_notes.txt#L51)