Executive brief
LimeSurvey Community Edition is an open-source survey and form creation platform. Version 7.0.5 contains a stored cross-site scripting vulnerability in the administrative question editor's replacement-fields dialog that allows authenticated administrators to inject malicious scripts, potentially compromising survey data, administrator accounts, or survey respondent information.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the replacement-fields dialog component of LimeSurvey's administrative question editor. The vulnerability requires authentication as an administrator to exploit. An attacker with administrative credentials can inject malicious JavaScript into the replacement-fields dialog, which is then stored and executed in the browsers of other administrators or users who view the affected questions. This allows session hijacking, credential theft, or manipulation of survey content and responses.
Affected products
- LimeSurvey Community Edition 7.0.5