First published: Tue Nov 15 2022(Updated: )
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Limesurvey Limesurvey | =5.4.4 | |
=5.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this LimeSurvey vulnerability is CVE-2022-43279.
CVE-2022-43279 has a severity rating of 7.2 (high).
CVE-2022-43279 affects LimeSurvey version 5.4.4.
CVE-2022-43279 belongs to CWE category 89.
To fix the SQL injection vulnerability in LimeSurvey v5.4.4, you should update to a patched version or apply the recommended security patches.