CVE-2018-17003: XSS
Published Sep 21, 2018
·Updated
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveylstitle parameter to /index.php?r=admin/survey/sa/insert.
Affected Software
1 affected component
Limesurvey LimeSurvey=3.14.7
Event History
Sep 21, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this LimeSurvey vulnerability?
The vulnerability ID for this LimeSurvey vulnerability is CVE-2018-17003.
2
What is the severity of CVE-2018-17003?
The severity of CVE-2018-17003 is medium with a CVSS score of 6.1.
3
What is the affected software for this vulnerability?
The affected software for this vulnerability is LimeSurvey version 3.14.7.
4
What type of vulnerability is CVE-2018-17003?
CVE-2018-17003 is a combination of HTML Injection and Stored XSS vulnerability.
5
How can I fix CVE-2018-17003 in LimeSurvey?
To fix CVE-2018-17003 in LimeSurvey, it is recommended to upgrade to a patched version of LimeSurvey.