A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-11-17T14:21:20

Updated: 2024-08-04T15:40:36.944Z

Reserved: 2020-09-21T00:00:00

Link: CVE-2020-25798

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-11-17T15:15:12.163

Modified: 2020-11-27T14:37:16.623

Link: CVE-2020-25798

cve-icon Redhat

No data.