CVE-2019-16186: High severity limesurvey vulnerability
Published Sep 9, 2019
·Updated
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
Affected Software
1 affected component
Limesurvey LimeSurvey<3.17.14
Remediation
Event History
Sep 9, 2019
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Limesurvey issue?
The vulnerability ID for this Limesurvey issue is CVE-2019-16186.
2
What is the severity of CVE-2019-16186?
The severity of CVE-2019-16186 is high with a CVSS score of 7.2.
3
What is affected by CVE-2019-16186?
Limesurvey versions up to exclusive 3.17.14 are affected by CVE-2019-16186.
4
How can admin users access the plugin manager without proper permissions?
In Limesurvey before version 3.17.14, admin users can access the plugin manager without proper permissions.
5
How can I fix CVE-2019-16186?
Upgrade Limesurvey to version 3.17.14 or later to mitigate the vulnerability.