First published: Tue Sep 03 2024(Updated: )
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LimeSurvey | <6.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42902 has been assigned a high severity rating due to its potential to allow arbitrary code execution.
To mitigate CVE-2024-42902, upgrade to LimeSurvey version 6.6.3 or later, which addresses this vulnerability.
CVE-2024-42902 affects LimeSurvey versions 6.6.2 and earlier.
The vulnerability in CVE-2024-42902 exists in the js_localize.php function.
CVE-2024-42902 allows attackers to execute arbitrary code through crafted payloads injected into the lng parameter.