Description
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
Remediation
References
Related Vulnerabilities
Joomla Incorrect Authorization Vulnerability (CVE-2018-17857)
WordPress 5.0.x Multiple Vulnerabilities (5.0 - 5.0.16)
Liferay DXP Deserialization of Untrusted Data Vulnerability (CVE-2020-15842)
OpenSSL CVE-2021-4160 Vulnerability (CVE-2021-4160)
WordPress Plugin WassUp Real Time Analytics Cross-Site Scripting (1.8.3)