CVE-2021-42112
08.10.2021, 21:15
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Vendor | Product | Version |
---|---|---|
limesurvey | limesurvey | 3.0.0 ≤ 𝑥 ≤ 3.27.18 |
𝑥
= Vulnerable software versions
References