CVE-2020-11455: Path Traversal
Published Apr 1, 2020
·Updated
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.
Affected Software
3 affected components
Limesurvey LimeSurvey<=4.1.11
Limesurvey LimeSurvey=4.1.12
Limesurvey LimeSurvey=4.1.12-200324
Remediation
Event History
Apr 1, 2020
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this LimeSurvey vulnerability?
The vulnerability ID is CVE-2020-11455.
2
What is the severity rating of CVE-2020-11455?
The severity rating of CVE-2020-11455 is critical with a score of 9.8.
3
What is the affected software for CVE-2020-11455?
The affected software for CVE-2020-11455 is LimeSurvey versions up to and including 4.1.11.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through a path traversal attack in the LimeSurveyFileManager.php file.
5
Are there any patches or fixes available for CVE-2020-11455?
Yes, LimeSurvey has released a fixed version 4.1.12 that addresses CVE-2020-11455.