In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.
| Software | From | Fixed in |
|---|---|---|
limesurvey / limesurvey
|
3.14.7 | 3.14.7.x |