CVE-2021-44967: Malicious File Upload
Published Feb 22, 2022
·Updated
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file.
Affected Software
1 affected component
Limesurvey LimeSurvey=5.2.4
Event History
Feb 22, 2022
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this LimeSurvey vulnerability?
The vulnerability ID for this LimeSurvey vulnerability is CVE-2021-44967.
2
What is the severity level of CVE-2021-44967?
The severity level of CVE-2021-44967 is critical.
3
How does the LimeSurvey vulnerability CVE-2021-44967 work?
The LimeSurvey vulnerability CVE-2021-44967 allows a remote malicious user to upload an arbitrary PHP code file via the upload and install plugins function, leading to remote code execution (RCE).
4
Which version of LimeSurvey is affected by CVE-2021-44967?
LimeSurvey version 5.2.4 is affected by CVE-2021-44967.
5
Is there a fix available for CVE-2021-44967?
Yes, upgrading to a fixed version (if available) or applying the vendor's recommended patches/updates can fix CVE-2021-44967.