Description
LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.
Remediation
References
Related Vulnerabilities
WordPress Plugin Calendar Multiple Cross-Site Scripting Vulnerabilities (1.2.1)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3553)
WordPress Plugin Image Metadata Cruncher Multiple Vulnerabilities (1.8)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2020-9546)
WordPress Plugin Super Interactive Maps for WordPress Arbitrary File Upload (1.9)