Description
A Reflected Cross-Site Scripting (XSS) affects LimeSurvey versions prior to 6.15.11+250909, due to the lack of validation of gid parameter in getInstance() function in application/models/QuestionCreate.php. This allows an attacker to craft a malicious URL and compromise the logged in user.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Google Review Slider SQL Injection (6.1)
Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-36400)
OpenSSL Missing Cryptographic Step Vulnerability (CVE-2025-69418)
IBM WebSEAL Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2018-1803)