Description
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
Remediation
References
Related Vulnerabilities
WordPress Plugin CWIS-Antivirus Security Scanner Unspecified Vulnerability (2.3.2)
MySQL CVE-2017-3329 Vulnerability (CVE-2017-3329)
PrestaShop Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-25170)
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.8)
WordPress Plugin Erident Custom Login and Dashboard Cross-Site Request Forgery (3.4.1)