The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
| Software | From | Fixed in |
|---|---|---|
limesurvey / limesurvey
|
3.0.0 | 3.27.18.x |
limesurvey / limesurvey
|
- | 3.27.19 |