The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
References
Link | Resource |
---|---|
https://github.com/LimeSurvey/LimeSurvey/commit/d56619a50cfd191bbffd0adb660638a5e438070d | Patch Third Party Advisory |
https://bugs.limesurvey.org/view.php?id=17562 | Permissions Required |
https://www.on-x.com/sites/default/files/on-x_-_security_advisory_-_limesurvey_-_cve-2021-42112.pdf | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-10-08 14:15
Updated : 2021-12-02 19:01
NVD link : CVE-2021-42112
Mitre link : CVE-2021-42112
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
limesurvey
- limesurvey