Improper Access Control in LimeSurvey Admin Panel
CVE-2019-16185
7.2HIGH
What is CVE-2019-16185?
An improper access control vulnerability exists in LimeSurvey prior to version 3.17.14, enabling admin users to access, modify, or erase reserved menu items without the necessary permissions. This flaw can result in unauthorized actions being performed within the application, potentially compromising the integrity and confidentiality of the data managed by LimeSurvey.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved