Junglewise Threat Intelligence

CVE-2026-50636: LimeSurvey SQL injection in RemoteControl API participant methods

CVE-2026-50636 · Severity: high · CVSS 8.8 · Published 2026-06-09

Technologies: LimeSurvey, limesurvey/limesurvey (Packagist). Vendors: LimeSurvey, Packagist.

Executive brief

LimeSurvey, a popular open-source survey platform, contains a security flaw in its remote management interface. An authenticated user with basic survey permissions can exploit this to gain full control over the database. This could lead to the theft of sensitive participant data, exposure of administrator passwords, or the complete deletion of survey records.

Technical details

A SQL injection vulnerability exists in LimeSurvey's RemoteControl API within the invite_participants and remind_participants methods. The root cause is the lack of input validation or parameterization when passing a caller-supplied token-ID array into the TokenDynamic::findUninvited() function, which directly concatenates values into a 'tid IN' SQL clause. Because the application uses PDO with emulated prepared statements (emulatePrepare = true) and does not disable multi-statements, attackers can perform stacked queries. This allows remote, authenticated attackers with 'tokens/update' permissions to read sensitive data (like bcrypt hashes in the lime_users table) via time-based blind techniques or perform arbitrary write/delete operations. The attack requires the RemoteControl interface (JSON/XML) to be enabled.

Affected products

  • LimeSurvey LimeSurvey <= 7.0.0-beta1

Timeline

  • 2026-06-04: other: Fix submitted via pull request 5031
  • 2026-06-09: disclosed: Initial advisory publication
  • 2026-06-09: advisory: GitHub Advisory GHSA-pr6f-87hf-hx24 published

References

Related threats