Impact
LimeSurvey Community Edition 7.0.14 contains a reflected cross‑site scripting flaw that is triggered when an administrator imports a CSV file with an invalid column name. The attacker can embed arbitrary JavaScript into the import result page, which will execute in the context of any user who views that page. This may lead to cookie theft, session hijacking, defacement, or the execution of malicious actions on behalf of the victim. The vulnerability does not grant server‑side code execution or direct access to the file system.
Affected Systems
The flaw affects LimeSurvey Community Edition 7.0.14 running on Linux, macOS, and Windows platforms. Only installations using that exact version are impacted; newer versions may have the issue resolved.
Risk and Exploitability
The CVSS score of 7.4 indicates a high impact when combined with the possibility of injection through an administrative operation. Exploitation requires administrative access to the survey‑participant CSV import feature, and the attack vector is web‑based via a privileged user interface. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying that no confirmed widespread exploitation has been reported yet. Nonetheless, the attacker can transform the admin UI into a vector for phishing or data theft, making the risk significant for organizations with unprotected survey administration.
OpenCVE Enrichment