CSV Injection Vulnerability in Limesurvey by LimeSurvey GmbH
CVE-2019-16184

9.8CRITICAL

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
9 September 2019

What is CVE-2019-16184?

A security flaw was identified in Limesurvey versions prior to 3.17.14, which exposes the platform to a CSV injection attack. This vulnerability permits malicious survey participants to inject arbitrary commands into their survey responses. These injected commands are then included in export files, enabling attackers to manipulate the data output and potentially execute harmful code when the CSV file is opened in spreadsheet applications. Proper validation and sanitization of input data are essential to mitigate this risk and ensure the integrity of survey data.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.