Description
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
Remediation
References
Related Vulnerabilities
WordPress 4.1.x Multiple Vulnerabilities (4.1 - 4.1.22)
phpBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1627)
MediaWiki Other Vulnerability (CVE-2006-0322)
Drupal Core 8.5.x Cross-Site Scripting (8.5.0 - 8.5.14)
WordPress Plugin jRSS Widget Server-Side Request Forgery (1.2)