
We found results for “”
CVE-2024-6933
Good to know:

Date: July 20, 2024
A vulnerability was found in LimeSurvey 6.5.14-240624. It has been rated as critical. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. The manipulation of the argument language leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271988. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89Top Fix

Upgrade Version
Upgrade to version limesurvey/limesurvey - dev-master-innodb;limesurvey/limesurvey - 2.2.5;limesurvey/limesurvey - dev-develop;limesurvey/limesurvey - 5.3.26+220720;limesurvey/limesurvey - dev-fix-spss-token-length;limesurvey/limesurvey - dev-dev-clean-survey-model;limesurvey/limesurvey - dev-fieldmap2;limesurvey/limesurvey - 5.3.7+220328;limesurvey/limesurvey - dev-snyk-fix-76cf46bd82f4347fa5bd130cdd788057;limesurvey/limesurvey - dev-anonymize-tokens;limesurvey/limesurvey - dev-tests-add-dir;limesurvey/limesurvey - 5.0.0+210526;limesurvey/limesurvey - dev-snyk-upgrade-80cca6dada6ad6307686632d311a7ef6;limesurvey/limesurvey - dev-dependabot/npm_and_yarn/assets/packages/lstutorial/terser-5.14.2;limesurvey/limesurvey - dev-dependabot/npm_and_yarn/assets/packages/lstutorial/loader-utils-2.0.3;limesurvey/limesurvey - dev-findfix6
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | LOW |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | LOW |
Authentication (AU): | SINGLE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |