Description
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.0.x Multiple Cross-Site Scripting Vulnerabilities (1.0.0 - 1.0.10)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-4391)
WordPress Plugin Twenty20 Image Before-After Malicious Code (1.6.3)
WordPress Plugin Custom Fields Search by BestWebSoft Cross-Site Scripting (1.3.1)