CSV Injection Vulnerability in LimeSurvey by LimeSurvey
CVE-2024-42901

Currently unrated

Key Information:

Vendor

LimeSurvey

Vendor
CVE Published:
3 September 2024

What is CVE-2024-42901?

A CSV injection vulnerability exists in LimeSurvey version 6.5.12 that enables attackers to upload specially crafted CSV files to execute arbitrary code on the server. This vulnerability can be exploited if an unsuspecting user opens the manipulated CSV file, resulting in potential exposure of sensitive information or unauthorized actions within the application. It is crucial for users of LimeSurvey to update to the latest version and implement security measures to mitigate the risk associated with this vulnerability.

References

Timeline

  • Vulnerability published

.