Description
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 29 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey. | |
| Title | LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations | |
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:linux:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:macos:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-09-29T02:20:43.077Z
Reserved: 2026-09-24T21:11:19.206Z
Link: CVE-2026-97685
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-639
Authorization Bypass Through User-Controlled Key