Description
|
|
Joshua Tiago has discovered a vulnerability in LimeSurvey, which can be exploited by malicious people to conduct script insertion attacks.
Input passed via certain text fields to surveys is not properly sanitised before being used as tooltip when browsing survey results. This can be exploited to insert HTML and script code, which will be executed in an administrative user's browser session in context of an affected site if malicious data is viewed.
The vulnerability is confirmed in version 1.91+ Build 11343-20111108. Prior versions may also be affected.
|