CVE-2024-42902: Code Injection
Published Sep 3, 2024
·Updated
An issue in the jslocalize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the jslocalize.php function
Affected Software
2 affected components
Limesurvey LimeSurvey<6.6.2
Limesurvey LimeSurvey<=6.6.2
Event History
Sep 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42902?
CVE-2024-42902 has been assigned a high severity rating due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2024-42902?
To mitigate CVE-2024-42902, upgrade to LimeSurvey version 6.6.3 or later, which addresses this vulnerability.
3
What versions of LimeSurvey are affected by CVE-2024-42902?
CVE-2024-42902 affects LimeSurvey versions 6.6.2 and earlier.
4
What specific function is vulnerable in CVE-2024-42902?
The vulnerability in CVE-2024-42902 exists in the js_localize.php function.
5
What type of attack does CVE-2024-42902 facilitate?
CVE-2024-42902 allows attackers to execute arbitrary code through crafted payloads injected into the lng parameter.