Impact
The flaw permits an authenticated low‑privileged user, such as a survey creator, to embed JavaScript in a quota message. When respondents view that message, the payload runs in their browsers in the context of the survey page, allowing the attacker to execute arbitrary client‑side code.
Affected Systems
LimeSurvey Community Edition 7.0.5 on Linux, macOS, and Windows. The affected product is the standard LimeSurvey application for these operating systems.
Risk and Exploitability
The CVSS score is 7.2, indicating high severity. The EPSS score is not available, so exploitation frequency is unknown. The vulnerability is not listed in CISA KEV. It can be exploited by any user with permission to edit a survey’s quota messages; the attacker stores malicious JavaScript, which is then executed when respondents load the affected survey.
OpenCVE Enrichment