Description
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
Remediation
References
Related Vulnerabilities
Jboss EAP Incorrect Authorization Vulnerability (CVE-2014-0169)
Nginx Integer Overflow or Wraparound Vulnerability (CVE-2017-20005)
Drupal Incorrect Authorization Vulnerability (CVE-2017-6377)
WordPress Plugin Appointments Scheduler Cross-Site Scripting (1.5)
WordPress Plugin WP eCommerce 'wpsc-transaction_results_functions.php' SQL Injection (3.8.7.5)