SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.
References
Configurations
History
21 Nov 2024, 02:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/75301 - | |
References | () https://bugs.limesurvey.org/view.php?id=9694 - | |
References | () https://github.com/LimeSurvey/LimeSurvey/commit/b09edc0dbd18d8459ade4c7c941e562c16564f9e - | |
References | () https://github.com/LimeSurvey/LimeSurvey/commit/e15861a65b7028adfc23ef6af8563f645e318548 - | |
References | () https://github.com/LimeSurvey/LimeSurvey/pull/331 - |
Information
Published : 2015-06-18 10:59
Updated : 2024-11-21 02:31
NVD link : CVE-2015-4628
Mitre link : CVE-2015-4628
CVE.ORG link : CVE-2015-4628
JSON object : View
Products Affected
limesurvey
- limesurvey
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')