Description
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
Remediation
References
Related Vulnerabilities
WordPress Plugin NewsPlugin Cross-Site Request Forgery (1.0.18)
WordPress Plugin youForms for WordPress-Creating Forms for CopeCart Cross-Site Scripting (1.0.5)
Atlassian Jira CVE-2019-20413 Vulnerability (CVE-2019-20413)
WordPress Plugin MW WP Form Security Bypass (4.4.5)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-1927)