Description
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Welcome-message text fields.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Coder-add custom html, css and js code Cross-Site Request Forgery (2.5.2)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2009-1891)
WordPress Plugin Pinterest 'Pin It' Button Cross-Site Scripting (2.0.8)
WordPress Plugin PHP Speedy 'admin_container.php' Remote PHP Code Execution (0.5.2)