SQL Injection Vulnerability in LimeSurvey Web Application
CVE-2022-43279
7.2HIGH
What is CVE-2022-43279?
LimeSurvey versions prior to 5.0.4 have been identified to contain a SQL injection vulnerability that can be exploited through the update.php component located in the application/views/themeOptions directory. This flaw allows attackers to execute unauthorized SQL queries, potentially compromising the database and compromising sensitive information. It is crucial for users to update their installations to the latest version to secure their applications and prevent possible exploits.