Description
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21323 Vulnerability (CVE-2022-21323)
Drupal Core 8.6.x Directory Traversal (8.6.0 - 8.6.15)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-8235)
WordPress Plugin Smart Email Alerts Cross-Site Scripting (1.0.10)
WordPress Plugin WP PHP widget Information Disclosure (1.0.2)