Description
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
Remediation
References
Related Vulnerabilities
Apache Tomcat Improper Encoding or Escaping of Output Vulnerability (CVE-2021-30640)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-7570)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-28333)
Jenkins Insufficient Session Expiration Vulnerability (CVE-2019-1003004)