Description
In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
Remediation
References
Related Vulnerabilities
MediaWiki Improper Authentication Vulnerability (CVE-2021-30158)
WordPress Plugin WP Job Manager PHP Object Injection (1.31.2)
MySQL CVE-2018-2812 Vulnerability (CVE-2018-2812)
WordPress Plugin Pixabay Images Multiple Vulnerabilities (2.3)
e107 Credentials Management Errors Vulnerability (CVE-2013-7305)