View Issue Details

This bug affects 1 person(s).
 252
IDProjectCategoryView StatusLast Update
15411Bug reportsSecuritypublic2020-03-09 15:37
ReporterDenisChenu Assigned ToDenisChenu  
PriorityimmediateSeverityminor 
Status closedResolutionfixed 
Product Version3.18.x 
Fixed in Version3.18.x 
Summary15411: CVE-2019-17660 : XSS in quick edit
Description

See
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17660
and
https://www.limesurvey.org/forum/team-only/119455-cve-2019-17660-limesurvey

Steps To Reproduce

See github

Additional Information

Seems permission:read are not checked to view this page.

TagsNo tags attached.
Bug heat252
Complete LimeSurvey version number (& build)3.19.1
I will donate to the project if issue is resolvedNo
Browsernot relevant
Database type & versionnot relevant
Server OS (if known)not relevant
Webserver software & version (if known)not relevant
PHP Versionnot relevant

Users monitoring this issue

There are no users monitoring this issue.

Issue History

Date Modified Username Field Change
2019-10-17 09:12 DenisChenu New Issue
2019-10-17 09:12 DenisChenu Assigned To => DenisChenu
2019-10-17 09:12 DenisChenu Status new => assigned
2019-10-17 09:13 DenisChenu Priority none => immediate
2019-10-17 11:30 DenisChenu Status assigned => resolved
2019-10-17 11:30 DenisChenu Resolution open => fixed
2019-10-17 11:30 DenisChenu Fixed in Version => 3.18.x
2019-10-17 11:30 DenisChenu Note Added: 54077
2020-03-09 15:37 c_schmitz Status resolved => closed