Description
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Body Class Cross-Site Request Forgery (0.6.0)
Apache HTTP Server Other Vulnerability (CVE-2001-1072)
WordPress Plugin Pinterest Automatic Pin Security Bypass (4.14.3)
Drupal Other Vulnerability (CVE-2006-2260)
Oracle Database Server CVE-2020-2511 Vulnerability (CVE-2020-2511)