CVE-2022-43279: SQL Injection
Published Nov 15, 2022
·Updated
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
Other sources
LimeSurvey v5.4.4 was discovered to contain a SQL injection vulnerability via the component /application/views/themeOptions/update.php.
Affected Software
1 affected component
Limesurvey LimeSurvey=5.4.4
Event History
Nov 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this LimeSurvey vulnerability?
The vulnerability ID for this LimeSurvey vulnerability is CVE-2022-43279.
2
What is the severity rating for CVE-2022-43279?
CVE-2022-43279 has a severity rating of 7.2 (high).
3
What is the affected software version for CVE-2022-43279?
CVE-2022-43279 affects LimeSurvey version 5.4.4.
4
What is the CWE category for CVE-2022-43279?
CVE-2022-43279 belongs to CWE category 89.
5
How can I fix the SQL injection vulnerability in LimeSurvey v5.4.4?
To fix the SQL injection vulnerability in LimeSurvey v5.4.4, you should update to a patched version or apply the recommended security patches.