CVE-2020-23710: XSS
Published Jun 28, 2021
·Updated
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
Affected Software
1 affected component
Limesurvey LimeSurvey=4.2.5
Remediation
Event History
Jun 28, 2021
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23710?
CVE-2020-23710 is a Cross Site Scripting (XSS) vulnerability in LimeSurvey 4.2.5.
2
How severe is CVE-2020-23710?
CVE-2020-23710 has a severity rating of 5.4 (medium).
3
How does CVE-2020-23710 affect LimeSurvey 4.2.5?
CVE-2020-23710 affects LimeSurvey 4.2.5 through a Cross Site Scripting (XSS) vulnerability.
4
How can I fix the Cross Site Scripting (XSS) vulnerability in LimeSurvey 4.2.5?
To fix the Cross Site Scripting (XSS) vulnerability in LimeSurvey 4.2.5, apply the necessary patches recommended by the vendor or upgrade to a secure version.
5
Where can I find more information about CVE-2020-23710?
More information about CVE-2020-23710 can be found at the following link: [GitHub Pull Request](https://github.com/LimeSurvey/LimeSurvey/pull/1441#partial-pull-merging)