Cross-Site Scripting Vulnerability in LimeSurvey by LimeSurvey
CVE-2018-10228
6.1MEDIUM
What is CVE-2018-10228?
A cross-site scripting vulnerability exists in the LimeSurvey application, specifically within the admin theme controller. This flaw allows remote attackers to execute arbitrary web scripts or inject HTML content through the manipulation of the changes_cp parameter within the index.php/admin/themes/sa/templatesavechanges URI. This could potentially compromise the integrity of user sessions and lead to unauthorized actions within the application.