Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.
Software | From | Fixed in |
---|---|---|
limesurvey / limesurvey | 1.80+ | 1.80+.x |
limesurvey / limesurvey | 1.72 | 1.72.x |
limesurvey / limesurvey | 1.85 | 1.85.x |
limesurvey / limesurvey | 1.53+ | 1.53+.x |
limesurvey / limesurvey | - | 1.91\+.x |
limesurvey / limesurvey | 1.52 | 1.52.x |
limesurvey / limesurvey | 1.87+ | 1.87+.x |
limesurvey / limesurvey | 1.86 | 1.86.x |
limesurvey / limesurvey | 1.90+ | 1.90+.x |
limesurvey / limesurvey | 1.81+ | 1.81+.x |
limesurvey / limesurvey | 1.70+ | 1.70+.x |
limesurvey / limesurvey | 1.50 | 1.50.x |
limesurvey / limesurvey | 1.71+ | 1.71+.x |
limesurvey / limesurvey | 1.01 | 1.01.x |
limesurvey / limesurvey | 1.82+ | 1.82+.x |