Description
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
Remediation
References
Related Vulnerabilities
Jboss EAP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2017-12629)
Atlassian Jira CVE-2021-39116 Vulnerability (CVE-2021-39116)
WordPress Plugin Admin Menu Cross-Site Scripting (1.1)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2018-1318)
WordPress Plugin Crelly Slider Arbitrary File Upload (1.3.4)