CVE-2019-16184: Critical severity limesurvey vulnerability
Published Sep 9, 2019
·Updated
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
Affected Software
1 affected component
Limesurvey LimeSurvey<3.17.14
Remediation
Event History
Sep 9, 2019
CVE Published
via MITRE·08:27 PM
Data Sourced
via MITRE·08:27 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16184?
CVE-2019-16184 is a CSV injection vulnerability found in Limesurvey before 3.17.14.
2
How does CVE-2019-16184 affect Limesurvey?
CVE-2019-16184 allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
3
What is the severity of CVE-2019-16184?
CVE-2019-16184 has a severity rating of 9.8 (Critical).
4
Which version of Limesurvey is affected by CVE-2019-16184?
Limesurvey versions up to and excluding 3.17.14 are affected by CVE-2019-16184.
5
How can I fix CVE-2019-16184?
To fix CVE-2019-16184, you need to update Limesurvey to version 3.17.14 or later.