First published: Wed Apr 01 2020(Updated: )
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Limesurvey Limesurvey | <=4.1.11 | |
Limesurvey Limesurvey | =4.1.12 | |
Limesurvey Limesurvey | =4.1.12-200324 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-11455.
The severity rating of CVE-2020-11455 is critical with a score of 9.8.
The affected software for CVE-2020-11455 is LimeSurvey versions up to and including 4.1.11.
This vulnerability can be exploited through a path traversal attack in the LimeSurveyFileManager.php file.
Yes, LimeSurvey has released a fixed version 4.1.12 that addresses CVE-2020-11455.