CVE-2022-48008: Malicious File Upload
Published Jan 27, 2023
·Updated
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
Affected Software
1 affected component
Limesurvey LimeSurvey=5.4.15
Event History
Jan 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this arbitrary file upload vulnerability?
The vulnerability ID for this arbitrary file upload vulnerability is CVE-2022-48008.
2
What is the severity rating for CVE-2022-48008?
CVE-2022-48008 has a severity rating of 9.8 (critical).
3
How does the arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 work?
The arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code by uploading a crafted PHP file.
4
Which version of LimeSurvey is affected by CVE-2022-48008?
LimeSurvey version 5.4.15 is affected by CVE-2022-48008.
5
Is there a fix available for CVE-2022-48008?
Yes, a fix for CVE-2022-48008 is available. It is recommended to update to a version that is not affected by this vulnerability.