Description
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
Remediation
References
Related Vulnerabilities
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-8286)
WordPress Plugin WP Debugging Security Bypass (2.10.2)
Ruby CVE-2018-16396 Vulnerability (CVE-2018-16396)
MySQL Other Vulnerability (CVE-2005-2572)
Envoy Proxy Integer Overflow or Wraparound Vulnerability (CVE-2021-28682)