CVE-2020-36993: LimeSurvey <= 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parentid] parameters to execute arbitrary JavaScript in administrative contexts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36993?
CVE-2020-36993 is classified as a medium severity vulnerability due to its potential for persistent cross-site scripting.
How do I fix CVE-2020-36993?
To mitigate CVE-2020-36993, upgrade LimeSurvey to version 4.3.11 or later where the vulnerability is patched.
What impact does CVE-2020-36993 have on LimeSurvey users?
CVE-2020-36993 allows attackers to inject malicious scripts, potentially leading to unauthorized actions in the survey administration panel.
Are older versions of LimeSurvey at risk due to CVE-2020-36993?
Yes, versions of LimeSurvey up to and including 4.3.10 are vulnerable to CVE-2020-36993.
What actions should LimeSurvey administrators take regarding CVE-2020-36993?
LimeSurvey administrators should immediately upgrade to the latest version to protect against the vulnerability.