BIT-limesurvey-2020-25798

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/limesurvey/BIT-limesurvey-2020-25798.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-limesurvey-2020-25798
Aliases
Published
2024-03-06T10:56:40.304Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.

Database specific
{
    "cpes": [
        "cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / limesurvey

Package

Name
limesurvey
Purl
pkg:bitnami/limesurvey

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.21.2