Executive brief
LimeSurvey Community Edition is an open-source survey and form creation platform. In version 7.0.5, an authenticated user with minimal read-only permissions can bypass authorization checks to create or modify survey menu entries that should require administrative privileges. This allows an attacker with basic user access to manipulate administrative navigation records, potentially altering system behavior and configuration visibility.
Technical details
The vulnerability is an improper authorization flaw in the POST /index.php/admin/menuentries/sa/create endpoint. An authenticated user with only the global settings:read permission can invoke this endpoint to create new survey menu entries without possessing the required settings:update privilege. The endpoint fails to enforce proper role-based access controls and additionally allows submission of menu IDs that the intended update workflow restricts for non-superadministrators. Attack requires valid authentication but no special user interaction; the flaw is purely an authorization check bypass in the API endpoint.
Affected products
- LimeSurvey Community Edition 7.0.5
Timeline
- 2026-08-27: disclosed