SQL Injection Vulnerability in LimeSurvey by LimeSurvey Project
CVE-2019-25019
9.8CRITICAL
What is CVE-2019-25019?
A SQL injection vulnerability exists in LimeSurvey prior to version 4.0.0-RC4. This flaw allows an attacker to manipulate SQL queries through the participant model, potentially accessing or altering sensitive data. Proper sanitization of inputs is crucial to mitigate such security risks.