CVE-2022-29710: XSS
A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-29710?
CVE-2022-29710 is a cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below, which allows attackers to execute arbitrary web scripts or HTML via a crafted plugin.
How does CVE-2022-29710 impact LimeSurvey?
CVE-2022-29710 allows attackers to execute arbitrary web scripts or HTML, posing a risk to the integrity and security of LimeSurvey.
What is the severity of CVE-2022-29710?
CVE-2022-29710 has a severity rating of 6.1/10, which is considered medium.
Which versions of LimeSurvey are affected by CVE-2022-29710?
LimeSurvey versions up to and including v5.3.9 are affected by CVE-2022-29710.
How can I fix the CVE-2022-29710 vulnerability in LimeSurvey?
To fix the CVE-2022-29710 vulnerability, it is recommended to update LimeSurvey to a version higher than v5.3.9 by applying the patch provided by the vendor.