Description LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. Remediation References CVE-2019-25019 Related Vulnerabilities WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.1) WordPress 5.1.x Directory Traversal (5.1 - 5.1.18) Apache Traffic Server Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9518) WordPress Plugin Chained Quiz Cross-Site Scripting (1.1.8.1) MySQL CVE-2019-2758 Vulnerability (CVE-2019-2758) Severity Critical Classification CVE-2019-25019 CWE-138 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities