CVE-2019-16180: Medium severity limesurvey vulnerability
Published Sep 9, 2019
·Updated
Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
Affected Software
1 affected component
Limesurvey LimeSurvey<3.17.14
Remediation
Event History
Sep 9, 2019
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16180?
CVE-2019-16180 is a vulnerability in Limesurvey before version 3.17.14 that allows remote attackers to brute force the login form and enumerate usernames when the LDAP authentication method is used.
2
How can remote attackers exploit CVE-2019-16180?
Remote attackers can exploit CVE-2019-16180 by attempting to brute force the login form and enumerate usernames when the LDAP authentication method is used.
3
What is the severity of CVE-2019-16180?
The severity of CVE-2019-16180 is medium with a CVSS score of 5.3.
4
Which version of Limesurvey is affected by CVE-2019-16180?
Versions of Limesurvey up to but excluding version 3.17.14 are affected by CVE-2019-16180.
5
How can I fix CVE-2019-16180?
To fix CVE-2019-16180, update Limesurvey to version 3.17.14.