3.5
CVSSv2

CVE-2019-16172

Published: 09/09/2019 Updated: 13/02/2023
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

limesurvey limesurvey

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20190912-0 > ======================================================================= title: Stored and reflected XSS vulnerabilities product: LimeSurvey vulnerable version: <= 31713 fixed version: =>31714 CVE number: CVE-2019-16172, CVE-2019- ...
LimeSurvey versions 31713 and below suffer from reflective and persistent cross site scripting vulnerabilities ...