Vulnerability Description
LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelview_view.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Limesurvey | Limesurvey | 3.17.7\+190627 |
Related Weaknesses (CWE)
References
- https://github.com/LimeSurvey/LimeSurvey/commit/0b7391dff91b326284ca3fc5188b768bPatchThird Party Advisory
- https://github.com/LimeSurvey/LimeSurvey/commit/f2566f6978a77e3f0870079c45cda1c0PatchThird Party Advisory
- https://www.limesurvey.org/Vendor Advisory
- https://www.linkedin.com/in/michelecisternino/Third Party Advisory
- https://github.com/LimeSurvey/LimeSurvey/commit/0b7391dff91b326284ca3fc5188b768bPatchThird Party Advisory
- https://github.com/LimeSurvey/LimeSurvey/commit/f2566f6978a77e3f0870079c45cda1c0PatchThird Party Advisory
- https://www.limesurvey.org/Vendor Advisory
- https://www.linkedin.com/in/michelecisternino/Third Party Advisory
FAQ
What is CVE-2019-14512?
CVE-2019-14512 is a vulnerability with a CVSS score of 6.1 (MEDIUM). LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in application/views/admin/labels/labelview_view.php.
How severe is CVE-2019-14512?
CVE-2019-14512 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14512?
Check the references section above for vendor advisories and patch information. Affected products include: Limesurvey Limesurvey.