Cross Site Scripting Vulnerability in LimeSurvey by LimeSurvey Group
CVE-2025-70797
6.1MEDIUM
What is CVE-2025-70797?
A Cross Site Scripting vulnerability exists in LimeSurvey versions 6.15.20 and later, enabling remote attackers to inject and execute arbitrary scripts via the Box[title] and box[url] parameters. Successful exploitation of this flaw could allow attackers to compromise user sessions and perform unauthorized actions within the application.
