Impact
An authenticated stored cross‑site scripting flaw exists in the replacement‑fields dialog of the administrative question editor in LimeSurvey Community Edition 7.0.5. The flaw permits a logged‑in user with sufficient privileges to inject and store malicious script payloads that will execute in the browser context of any user who views the affected question. The injected scripts can deface the survey interface, steal authentication cookies, or perform other malicious actions on behalf of the viewer.
Affected Systems
This vulnerability affects LimeSurvey Community Edition version 7.0.5. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. Because the flaw requires authentication and is limited to the administrator interface, exploitation privilege is restricted to users who can edit questions. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at this time. Nevertheless, any compromised administrator account could be used to inject harmful content into user surveys.
OpenCVE Enrichment