CVE-2020-36993
EUVD-2020-3090128.01.2026, 13:15
LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| limesurvey | limesurvey | 𝑥 ≤ 4.3.10 |
𝑥
= Vulnerable software versions