First published: Sun Feb 14 2021(Updated: )
LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Limesurvey Limesurvey | <3.19.0 | |
Limesurvey Limesurvey | =4.0.0-alpha | |
Limesurvey Limesurvey | =4.0.0-beta | |
Limesurvey Limesurvey | =4.0.0-rc1 | |
Limesurvey Limesurvey | =4.0.0-rc2 | |
Limesurvey Limesurvey | =4.0.0-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-25019 is a vulnerability in LimeSurvey before 4.0.0-RC4 that allows SQL injection via the participant model.
CVE-2019-25019 has a severity rating of 9.8 (critical).
LimeSurvey versions up to and excluding 3.19.0, 4.0.0-alpha, 4.0.0-beta, 4.0.0-rc1, 4.0.0-rc2, and 4.0.0-rc3 are affected by CVE-2019-25019.
Upgrade your LimeSurvey installation to version 4.0.0-RC4 or later to fix CVE-2019-25019.
More information about CVE-2019-25019 can be found in the release notes on the LimeSurvey community website and the GitHub repository.