Description
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Automatic 'q' Parameter SQL Injection (2.0.3)
WordPress 4.0.x Possible SQL Injection Vulnerability (4.0 - 4.0.19)
PostgreSQL Other Vulnerability (CVE-2009-4136)
WordPress Plugin File Manager Information Disclosure (6.4)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-10202)