CVE-2023-44796: XSS
Published Nov 17, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the generaloptionspanel.php component.
Affected Software
1 affected component
Limesurvey LimeSurvey<6.2.9
Remediation
Patch Available
Event History
Nov 17, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Nov 18, 2023
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-44796?
CVE-2023-44796 is a Cross-Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925.
2
How severe is CVE-2023-44796?
The severity of CVE-2023-44796 is medium, with a CVSS score of 5.4.
3
How does CVE-2023-44796 affect LimeSurvey?
CVE-2023-44796 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component in LimeSurvey versions prior to 6.2.9-230925.
4
How can I fix CVE-2023-44796?
To fix CVE-2023-44796, it is recommended to update LimeSurvey to version 6.2.9-230925 or later.
5
What is the CWE ID for CVE-2023-44796?
The CWE ID for CVE-2023-44796 is CWE-79 (Cross-Site Scripting).