Impact
The flaw lies in LimeSurvey Community Edition 7.0.14 where import warning pages do not escape content coming from a crafted .lss file. An attacker can embed malicious scripts that will run in an administrator’s browser when the warning is displayed, enabling the execution of arbitrary code with the same privileges as the admin user. The weakness is a classic cross‑site scripting flaw.
Affected Systems
The vulnerability affects installations of LimeSurvey Community Edition 7.0.14 on Linux, macOS, and Windows operating systems. Any administrator who uses the web interface to import a .lss survey file is susceptible when that file contains malicious content.
Risk and Exploitability
With a CVSS score of 7.4 the issue is considered high severity, yet no EPSS score is available and the vulnerability is not included in the CISA KEV catalog. Exploitation requires the attacker to supply a malicious .lss file and trigger the import failure, thereby catching an administrative session. Successful exploitation allows the attacker to run arbitrary JavaScript, potentially leading to session hijacking, credential theft, or further compromise of the survey data.
OpenCVE Enrichment