4.3
CVSSv2

CVE-2014-5018

Published: 21/07/2014 Updated: 22/07/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote malicious users to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

limesurvey limesurvey 2.05\\+