CVE-2024-28710: Input Validation
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/limesurvey/limesurveyto a version that resolves this vulnerability.Fixed in 6.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28710?
CVE-2024-28710 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-28710?
To fix CVE-2024-28710, upgrade LimeSurvey to version 6.5.0+240319 or later.
What causes CVE-2024-28710 in LimeSurvey?
CVE-2024-28710 is caused by a lack of input validation and output encoding in the Alert Widget's message component.
Can CVE-2024-28710 be exploited remotely?
Yes, CVE-2024-28710 can be exploited remotely by an attacker to execute arbitrary code.
What versions of LimeSurvey are affected by CVE-2024-28710?
CVE-2024-28710 affects all versions of LimeSurvey prior to 6.5.0+240319.