Description
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Backup and Migrate-Backup Guard Unspecified Vulnerability (1.0.6)
WordPress Plugin Nextend Twitter Connect Cross-Site Scripting (1.5.1)
MySQL CVE-2013-2389 Vulnerability (CVE-2013-2389)
WordPress Plugin Gallery for Social Photo Unspecified Vulnerability (1.0.0.25)
WordPress Plugin UpdraftPlus WordPress Backup Multiple Vulnerabilities (1.16.58)