Description
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter.
Remediation
References
Related Vulnerabilities
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35141)
WordPress Plugin WP Booking Calendar Multiple Vulnerabilities (3.0.0)
Oracle JRE CVE-2013-2439 Vulnerability (CVE-2013-2439)
WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (5.6.1)
Oracle Database Server CVE-2020-2511 Vulnerability (CVE-2020-2511)