Impact
LimeSurvey Community Edition 7.0.5 contains a stored XSS flaw that allows an authenticated user with global settings:read permission to create a survey menu entry that stores attacker‑controlled data in the surveymenu_entries.data field, which is later rendered inside a single‑quoted HTML title attribute without proper encoding. The stored payload is executed in the browser of any user who opens the menu entry. Based on the description, an attacker might exploit this to session hijack, deface, or execute arbitrary scripts in the site context.
Affected Systems
The vulnerability applies to LimeSurvey Community Edition version 7.0.5 on all supported platforms, including Linux, macOS, and Windows.
Risk and Exploitability
The CVSS score of 8.4 reflects a moderate to high severity. The EPSS score is not available and the flaw is not listed in CISA KEV. Exploitation requires a legitimate login with read permission, after which an attacker can persistently embed malicious script in a menu entry that will be executed for all users who view it. Because the flaw is stored and not limited to a specific user, widespread impact is possible once an authorized user creates a malicious entry.
OpenCVE Enrichment