← Back

CVE-2019-16178

nvd nist
Published: Sep 9, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.

Affected (1)

1 product
Limesurvey
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.17.14

Timeline

No history available yet.