|
225221
|
7.5 |
HIGH
Network
|
limesurvey
|
limesurvey
|
Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side script.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-16187
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225222
|
7.2 |
HIGH
Network
|
limesurvey
|
limesurvey
|
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16186
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225223
|
7.2 |
HIGH
Network
|
limesurvey
|
limesurvey
|
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16185
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225224
|
9.8 |
CRITICAL
Network
|
limesurvey
|
limesurvey
|
A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-16184
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225225
|
2.7 |
LOW
Network
|
limesurvey
|
limesurvey
|
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16183
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225226
|
6.1 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16182
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225227
|
2.7 |
LOW
Network
|
limesurvey
|
limesurvey
|
In Limesurvey before 3.17.14, admin users can mark other users' notifications as read.
|
NVD-CWE-noinfo
|
CVE-2019-16181
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225228
|
5.3 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
|
NVD-CWE-noinfo
|
CVE-2019-16180
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225229
|
5.3 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16179
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225230
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of …
|
CWE-79
Cross-site Scripting
|
CVE-2019-16178
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|