Executive brief
LimeSurvey Community Edition is a popular open-source survey and form-building platform used by organizations to collect participant feedback and data. A SQL injection vulnerability in its Central Participant Database (CPDB) workflow allows authenticated users to bypass normal query restrictions and potentially read, modify, or delete survey participant data stored in the database, compromising data integrity and confidentiality.
Technical details
The vulnerability is an authenticated SQL injection in LimeSurvey Community Edition 7.0.5 located in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list. The flaw exists in the parameter handling of the CPDB copy functionality, allowing an authenticated attacker to inject arbitrary SQL commands. Attack requires valid user authentication to the LimeSurvey application. Successful exploitation enables an attacker to execute arbitrary SQL queries against the survey database, potentially exfiltrating sensitive participant information, altering survey data, or disrupting database operations. Patch availability has not been confirmed in the available advisory information.
Affected products
- LimeSurvey Community Edition 7.0.5
Timeline
- 2026-08-14: disclosed