CVE-2019-17660: XSS
A cross-site scripting (XSS) vulnerability in admin/translate/translateheaderview.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/index/surveyid/336819/lang/ PATHINFO.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability in LimeSurvey?
The vulnerability ID for this XSS vulnerability in LimeSurvey is CVE-2019-17660.
What is the affected software for this vulnerability?
The affected software is LimeSurvey version up to and including 3.19.1.
What is the severity level of CVE-2019-17660?
The severity level of CVE-2019-17660 is medium.
How can an attacker exploit this vulnerability?
The attacker can exploit this vulnerability by injecting arbitrary web script or HTML via the 'tolang' parameter.
Is there a fix available for this vulnerability?
Yes, LimeSurvey has released patches to address this vulnerability. Updating to the latest version of LimeSurvey (beyond 3.19.1) will fix the issue.