LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding.
This issue affects LimeSurvey: 7.0.5.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Limesurvey Limesurvey
cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:windows:*:*:*:*:*
|
— | — |
|
Limesurvey Limesurvey
cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:macos:*:*:*:*:*
|
— | — |
|
Limesurvey Limesurvey
cpe:2.3:a:limesurvey:limesurvey:7.0.5:*:linux:*:*:*:*:*
|
— | — |