A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Feb 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding. |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-20T03:12:37.814Z
Reserved: 2021-12-13T00:00:00.000Z
Link: CVE-2021-44967
No data.
Status : Modified
Published: 2022-02-24T15:15:24.547
Modified: 2025-02-20T03:15:11.197
Link: CVE-2021-44967
No data.
OpenCVE Enrichment
No data.