Description
A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the logged in user.
Remediation
References
Related Vulnerabilities
WordPress Plugin Real Estate Website Builder 'ajax_action' Parameter Cross-Site Scripting (0.1.0)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3545)
Serendipity Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1916)