CVE-2024-6933
This manipulation of the argument Language causes sql injection.
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. This manipulation of the argument Language causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 6.6.2+240827 can resolve this issue. Patch name: d656d2c7980b7642560977f4780e64533a68e13d. You should upgrade the affected component.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-89
- Affected
- limesurvey/limesurvey
- Source
- cna@vuldb.com
References
- https://community.limesurvey.org/downloads/Product
- https://github.com/Hebing123/cve/issues/55Exploit, Issue Tracking, Third Party Advisory
- https://github.com/LimeSurvey/LimeSurvey/commit/d656d2c7980b7642560977f4780e64533a68e13dPatch
- https://vuldb.com/?ctiid.271988Permissions Required, VDB Entry
- https://vuldb.com/?id.271988Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.372007Third Party Advisory, VDB Entry
- https://github.com/Hebing123/cve/issues/55Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.271988Permissions Required, VDB Entry
- https://vuldb.com/?id.271988Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.372007Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.