CVE-2024-6933: LimeSurvey Survey General Settings updatesurveylocalesettings_generalsettings actionUpdateSurveyLocaleSettingsGeneralSettings sql injection
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettingsgeneralsettings of the component Survey General Settings Handler. This manipulation of the argument Language causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 6.6.2+240827 can resolve this issue. Patch name: d656d2c7980b7642560977f4780e64533a68e13d. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LimeSurvey 6.5.14-240624to a version that resolves this vulnerability.Fixed in 6.6.2+240827Patch d656d2c7980b7642560977f4780e64533a68e13d
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6933?
CVE-2024-6933 has been rated as critical.
Which version of LimeSurvey is affected by CVE-2024-6933?
LimeSurvey version 6.5.14-240624 is affected by CVE-2024-6933.
How do I fix CVE-2024-6933?
To fix CVE-2024-6933, upgrade to the latest version of LimeSurvey that has addressed this vulnerability.
What function is affected by CVE-2024-6933?
The function affected by CVE-2024-6933 is actionUpdateSurveyLocaleSettingsGeneralSettings.
Where can I find more details about CVE-2024-6933?
Detailed information about CVE-2024-6933 can typically be found in security advisories from LimeSurvey.