Vulnerability Description
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Limesurvey | Limesurvey | <= 1.91\+ |
Related Weaknesses (CWE)
References
- http://limesurvey.svn.sourceforge.net/viewvc/limesurvey/source/limesurvey/docs/r
- http://secunia.com/advisories/46831Vendor Advisory
- http://limesurvey.svn.sourceforge.net/viewvc/limesurvey/source/limesurvey/docs/r
- http://secunia.com/advisories/46831Vendor Advisory
FAQ
What is CVE-2011-5256?
CVE-2011-5256 is a vulnerability with a CVSS score of 2.6 (LOW). Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML vi...
How severe is CVE-2011-5256?
CVE-2011-5256 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-5256?
Check the references section above for vendor advisories and patch information. Affected products include: Limesurvey Limesurvey.