Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LimeSurvey 跨站脚本漏洞
Vulnerability Description
LimeSurvey(前称PHPSurveyor)是LimeSurvey(Limesurvey)团队的一套开源的在线问卷调查程序,它支持调查程序开发、调查问卷发布以及数据收集等功能。 LimeSurvey 3.6.2+180406 中/application/controller/admin/theme.php 中存在安全漏洞,该漏洞允许远程攻击者通过将 changes_cp 参数注入到 index.php/admin/themes/ 中的任意 Web 脚本或HTML sa/templatesavecha
CVSS Information
N/A
Vulnerability Type
N/A