Description
Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.
Remediation
References
Related Vulnerabilities
PHP Improper Handling of Exceptional Conditions Vulnerability (CVE-2014-1943)
WordPress Plugin GorillaForms-Custom Contact Forms Unspecified Vulnerability (2.0.3)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.23)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.75)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-44528)