CVE-2019-16178: XSS
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-16178?
CVE-2019-16178 is a stored cross-site scripting (XSS) vulnerability found in Limesurvey before version 3.17.14.
How does CVE-2019-16178 affect Limesurvey?
CVE-2019-16178 allows authenticated users with correct permissions to inject arbitrary web script or HTML through the titles of admin box buttons on the home page.
What is the severity of CVE-2019-16178?
The severity of CVE-2019-16178 is medium with a severity score of 5.4.
How can I fix CVE-2019-16178?
To fix CVE-2019-16178, you should update Limesurvey to version 3.17.14 or higher.
Where can I find more information about CVE-2019-16178?
You can find more information about CVE-2019-16178 in the official release notes and GitHub commit of Limesurvey version 3.17.14.