← Back

CVE-2012-4994

nvd nist
Published: Sep 19, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.

Affected (15)

1 product
Limesurvey
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Limesurvey
Up to 1.91\+
Version 1.01
Version 1.50
Version 1.52
Version 1.53+
Version 1.70+
Version 1.71+
Version 1.72
Version 1.80+
Version 1.81+
Version 1.82+
Version 1.85
Version 1.86
Version 1.87+
Version 1.90+

References (10)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.