LimeSurvey Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2019-9960 - Vulnerability Database

LimeSurvey Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2019-9960

Critical
Reference: CVE-2019-9960
Title: LimeSurvey Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1190225 allows a relative path.