CVE-2019-16182: XSS
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-16182?
CVE-2019-16182 is a reflected cross-site scripting (XSS) vulnerability found in Limesurvey before version 3.17.14.
How does CVE-2019-16182 affect Limesurvey?
CVE-2019-16182 allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.
What is the severity of CVE-2019-16182?
The severity of CVE-2019-16182 is medium with a CVSS score of 6.1.
How can I fix CVE-2019-16182?
To fix CVE-2019-16182, update Limesurvey to version 3.17.14 or later.
Where can I find more information about CVE-2019-16182?
You can find more information about CVE-2019-16182 in the references provided: [Link 1](https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R57), [Link 2](https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released).