Description
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 20 Feb 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding. |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-20T03:12:37.814Z
Reserved: 2021-12-13T00:00:00.000Z
Link: CVE-2021-44967
No data.
Status : Modified
Published: 2022-02-24T15:15:24.547
Modified: 2025-02-20T03:15:11.197
Link: CVE-2021-44967
No data.
OpenCVE Enrichment
No data.
Weaknesses