Description
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
Remediation
References
Related Vulnerabilities
WordPress Plugin Asgaros Forum Cross-Site Scripting (1.15.13)
Java Unspesificed Vulnerability (CVE-2019-2766)
OpenSSL Improper Input Validation Vulnerability (CVE-2015-1787)
Joomla! Core Security Bypass (1.6.0 - 3.6.0)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-32621)