LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-44967)
Description
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file.