LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.
| Software | From | Fixed in |
|---|---|---|
limesurvey / limesurvey
|
4.3.2 | 4.3.2.x |