Vulnerability Description
LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Limesurvey | Limesurvey | <= 4.3.10 |
Related Weaknesses (CWE)
References
- https://github.com/LimeSurvey/LimeSurvey/commit/3712854a8fd8d875c67640969a1d54c4Patch
- https://www.exploit-db.com/exploits/48762ExploitThird Party AdvisoryVDB Entry
- https://www.limesurvey.orgProduct
- https://www.vulncheck.com/advisories/limesurvey-survey-menu-persistent-cross-sitThird Party Advisory
FAQ
What is CVE-2020-36993?
CVE-2020-36993 is a vulnerability with a CVSS score of 5.4 (MEDIUM). LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[t...
How severe is CVE-2020-36993?
CVE-2020-36993 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36993?
Check the references section above for vendor advisories and patch information. Affected products include: Limesurvey Limesurvey.