Impact
LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection flaw in the Central Participant Database workflow that copies survey participant tokens into the central participant list. The vulnerability allows an authenticated user to inject malicious SQL statements, potentially revealing participant tokens and other sensitive data. The attackers could use the leaked tokens to masquerade as participants or to gain further access to the survey system.
Affected Systems
LimeSurvey Community Edition version 7.0.5 running on Linux, macOS, or Windows is affected. No other versions or editions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, and the EPSS score is not provided. The vulnerability requires valid authentication, so an attacker must first gain login credentials or have administrator privileges to exploit it. Because the flaw breaks into a centralized database, the impact can be widespread for the affected site, yet the lack of a publicly known exploit lowers the immediate threat. The vulnerability is not listed in CISA KEV catalog. However, with standard authenticated access, the risk of data exposure remains significant.
OpenCVE Enrichment