Description
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
Remediation
References
Related Vulnerabilities
WordPress Plugin Catch IDs Security Bypass (2.3)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5320)
WP Plugin Contact Form 7 Improper Validation of Integrity Check Value Vulnerability (CVE-2025-3247)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15733)