Description
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
Remediation
References
Related Vulnerabilities
MySQL CVE-2012-1757 Vulnerability (CVE-2012-1757)
Apache Tomcat Incorrect Authorization Vulnerability (CVE-2016-6797)
WordPress Plugin MSMC-Redirect After Comment Multiple Vulnerabilities (2.1.2)
WordPress Plugin iCopyright Toolbar 'icopyright_xml.php' SQL Injection (1.1.4)
Django Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-33571)