First published: Sun Jul 21 2024(Updated: )
A vulnerability was found in LimeSurvey 6.5.14-240624. It has been rated as critical. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. The manipulation of the argument language leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271988. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
LimeSurvey | =6.5.14-240624 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6933 has been rated as critical.
LimeSurvey version 6.5.14-240624 is affected by CVE-2024-6933.
To fix CVE-2024-6933, upgrade to the latest version of LimeSurvey that has addressed this vulnerability.
The function affected by CVE-2024-6933 is actionUpdateSurveyLocaleSettingsGeneralSettings.
Detailed information about CVE-2024-6933 can typically be found in security advisories from LimeSurvey.