Description
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
Remediation
References
Related Vulnerabilities
WordPress Plugin Import all XML, CSV & TXT into WordPress Security Bypass (6.4.1)
Django Improper Authentication Vulnerability (CVE-2014-0482)
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.4.6)
WordPress Plugin rtMedia for WordPress, BuddyPress and bbPress Cross-Site Scripting (3.7.38)