LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-17003 - Vulnerability Database
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-17003
Medium
Reference:
CVE-2018-17003
Title:
LimeSurvey Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In LimeSurvey 3.14.7 HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.phpradmin/survey/sa/insert.