Executive brief
LimeSurvey, a popular open-source survey tool, is vulnerable to a security flaw that allows unauthorized individuals to access its underlying database. An attacker could exploit this to steal sensitive information, including user credentials, private survey responses, and administrative data. Organizations using this software should update immediately to prevent data theft.
Technical details
A SQL injection vulnerability exists in LimeSurvey due to improper input validation of user-supplied data before it is used in database queries. The flaw allows a remote, unauthenticated attacker to manipulate SQL query logic by sending specially crafted requests to the application. Successful exploitation enables the attacker to execute arbitrary SQL queries, potentially leading to the unauthorized retrieval of sensitive data such as user credentials and survey results. The issue is resolved in version 6.15.4+250710.
Affected products
- LimeSurvey LimeSurvey before 6.15.4+250710
Timeline
- 2026-03-10: advisory: NVD publication date
- 2025-07-10: patched: Based on version naming convention 250710