Vulnerabilities > CVE-2014-5018 - Unspecified vulnerability in Limesurvey 2.05+

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
limesurvey

Summary

Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume. <a href="http://cwe.mitre.org/data/definitions/184.html" target="_blank">CWE-184: Incomplete Blacklist</a>

Vulnerable Configurations

Part Description Count
Application
Limesurvey
1