CVE-2019-16174: XEE
Published Sep 9, 2019
·Updated
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
Affected Software
1 affected component
Limesurvey LimeSurvey<3.17.14
Remediation
Event History
Sep 9, 2019
CVE Published
via MITRE·08:43 PM
Data Sourced
via MITRE·08:43 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16174?
CVE-2019-16174 is an XML injection vulnerability found in Limesurvey before version 3.17.14.
2
How does CVE-2019-16174 affect Limesurvey?
CVE-2019-16174 allows remote attackers to import specially crafted XML files and execute arbitrary code or compromise data integrity.
3
What is the severity of CVE-2019-16174?
CVE-2019-16174 has a severity score of 8.8, which is considered high.
4
How can I fix the CVE-2019-16174 vulnerability in Limesurvey?
To fix the CVE-2019-16174 vulnerability in Limesurvey, upgrade to version 3.17.14 or later.
5
Where can I find more information about CVE-2019-16174?
You can find more information about CVE-2019-16174 in the official Limesurvey updates and the GitHub commit.