Vulnerability Description
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Limesurvey | Limesurvey | < 6.2.9 |
Related Weaknesses (CWE)
References
- https://github.com/Hebing123/CVE-2023-44796/issues/1Exploit
- https://github.com/Hebing123/cve/issues/4
- https://github.com/LimeSurvey/LimeSurvey/pull/3483Patch
- https://github.com/limesurvey/limesurvey/commit/135511073c51c332613dd7fad9a8ca0aPatch
- https://github.com/Hebing123/CVE-2023-44796/issues/1Exploit
- https://github.com/Hebing123/cve/issues/4
- https://github.com/LimeSurvey/LimeSurvey/pull/3483Patch
- https://github.com/limesurvey/limesurvey/commit/135511073c51c332613dd7fad9a8ca0aPatch
FAQ
What is CVE-2023-44796?
CVE-2023-44796 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
How severe is CVE-2023-44796?
CVE-2023-44796 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-44796?
Check the references section above for vendor advisories and patch information. Affected products include: Limesurvey Limesurvey.