Description
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Remediation
References
Related Vulnerabilities
Artifactory Improper Privilege Management Vulnerability (CVE-2022-0668)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3278)
PHP Use After Free Vulnerability (CVE-2020-7068)
phpBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5173)
WordPress Plugin Catchers Helpdesk and Ticket system for Support Cross-Site Scripting (2.6.7)