CVE-2019-9960: Path Traversal
Published Mar 24, 2019
·Updated
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
Affected Software
1 affected component
Limesurvey LimeSurvey<=3.16.1\+190225
Remediation
Event History
Mar 24, 2019
CVE Published
via MITRE·12:27 AM
Data Sourced
via MITRE·12:27 AM
Description
Data Sourced
via NVD·01:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-9960.
2
What is the severity of CVE-2019-9960?
The severity of CVE-2019-9960 is critical with a severity value of 9.8.
3
What is the affected software of CVE-2019-9960?
The affected software of CVE-2019-9960 is LimeSurvey version up to and inclusive of 3.16.1+190225.
4
What does the downloadZip function in LimeSurvey do?
The downloadZip function in LimeSurvey allows a relative path.
5
Is there a fix available for CVE-2019-9960?
Yes, a fix is available. Please refer to the referenced link for more information.