LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2021-44967 - Vulnerability Database

LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability - CVE-2021-44967

High
Reference: CVE-2021-44967
Title: LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability
Overview:

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function which could let a remote malicious user upload an arbitrary PHP code file.