Description
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
Remediation
References
Related Vulnerabilities
WordPress Cross-Site Scripting Vulnerability (3.9 - 4.1.1)
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12605)
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9410)
WordPress Plugin WP Job Manager Cross-Site Request Forgery (1.25.2)