ZeroHour

CVE-2019-16182

CVSS 3.1
6.1 medium
EPSS
1%p64
Published
()
Modified
Description

A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.

Vendors
limesurvey
Products
limesurvey
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.