Vulnerabilities > CVE-2019-16174 - XXE vulnerability in Limesurvey
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R40
- https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R40
- https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released
- https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released