CVE-2019-14512: XSS
Published Mar 16, 2020
·Updated
LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelviewview.php.
Affected Software
1 affected component
Limesurvey LimeSurvey=3.17.7\+190627
Remediation
Event History
Mar 16, 2020
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this LimeSurvey vulnerability?
The vulnerability ID for this LimeSurvey vulnerability is CVE-2019-14512.
2
What is the severity of CVE-2019-14512?
The severity of CVE-2019-14512 is medium with a CVSS score of 6.1.
3
How does LimeSurvey 3.17.7+190627 have XSS?
LimeSurvey 3.17.7+190627 has XSS through Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelview_view.php.
4
How can I fix the XSS vulnerability in LimeSurvey 3.17.7+190627?
To fix the XSS vulnerability in LimeSurvey 3.17.7+190627, update to a version that includes the following commits: [commit link 1] and [commit link 2].
5
Where can I find more information about LimeSurvey?
You can find more information about LimeSurvey on the official LimeSurvey website [website link].