CVE-2020-11456: XSS
Published Apr 1, 2020
·Updated
LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and application/models/SurveysGroups.php (aka survey groups).
Affected Software
3 affected components
Limesurvey LimeSurvey<=4.1.11
Limesurvey LimeSurvey=4.1.12
Limesurvey LimeSurvey=4.1.12-200324
Remediation
Event History
Apr 1, 2020
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-11456?
The severity of CVE-2020-11456 is medium with a score of 5.4.
2
How does CVE-2020-11456 impact LimeSurvey?
CVE-2020-11456 allows for stored XSS attacks in LimeSurvey before version 4.1.12+200324.
3
Which versions of LimeSurvey are affected by CVE-2020-11456?
LimeSurvey versions up to and including 4.1.11, 4.1.12, and 4.1.12-200324 are affected by CVE-2020-11456.
4
How can I fix CVE-2020-11456?
To fix CVE-2020-11456, update LimeSurvey to version 4.1.12+200324 or higher.
5
Where can I find more information about CVE-2020-11456?
You can find more information about CVE-2020-11456 at the following references: [1] [2] [3].