CVE-2021-44967

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
9
HIGH
Affected
1
PROJECT

Description

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.

LimeSurvey Authenticated RCE
GitHubGitHub
24