CVE-2019-25019: SQL Injection
Published Feb 14, 2021
·Updated
LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.
Affected Software
6 affected components
Limesurvey LimeSurvey<3.19.0
Limesurvey LimeSurvey=4.0.0-alpha
Limesurvey LimeSurvey=4.0.0-beta
Limesurvey LimeSurvey=4.0.0-rc1
Limesurvey LimeSurvey=4.0.0-rc2
Limesurvey LimeSurvey=4.0.0-rc3
Event History
Feb 14, 2021
CVE Published
via MITRE·03:22 AM
Data Sourced
via MITRE·03:22 AM
Description
Frequently Asked Questions
1
What is CVE-2019-25019?
CVE-2019-25019 is a vulnerability in LimeSurvey before 4.0.0-RC4 that allows SQL injection via the participant model.
2
How severe is CVE-2019-25019?
CVE-2019-25019 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2019-25019?
LimeSurvey versions up to and excluding 3.19.0, 4.0.0-alpha, 4.0.0-beta, 4.0.0-rc1, 4.0.0-rc2, and 4.0.0-rc3 are affected by CVE-2019-25019.
4
How can I fix CVE-2019-25019?
Upgrade your LimeSurvey installation to version 4.0.0-RC4 or later to fix CVE-2019-25019.
5
Where can I find more information about CVE-2019-25019?
More information about CVE-2019-25019 can be found in the release notes on the LimeSurvey community website and the GitHub repository.