View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update | ||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
20125 | Bug reports | Security | public | 2025-05-27 07:23 | 2025-05-27 08:49 | ||||||||||||||||||||||||||||||||||||
Reporter | manfredsteger | Assigned To | |||||||||||||||||||||||||||||||||||||||
Priority | none | Severity | partial_block | ||||||||||||||||||||||||||||||||||||||
Status | new | Resolution | open | ||||||||||||||||||||||||||||||||||||||
Product Version | 6.6.x | ||||||||||||||||||||||||||||||||||||||||
Summary | 20125: Third-party components affected by known vulnerabilities (CVEs) | ||||||||||||||||||||||||||||||||||||||||
Description | During a security review of LimeSurvey 6.10.x, several third-party components were identified that are outdated and affected by known vulnerabilities (CVEs). These components pose potential security risks and should be updated to their latest secure versions. The application uses the following software packages with known vulnerabilities:
� Recommended Actions
| ||||||||||||||||||||||||||||||||||||||||
Steps To Reproduce | OWASP Test and pentest-tools.com used | ||||||||||||||||||||||||||||||||||||||||
Tags | No tags attached. | ||||||||||||||||||||||||||||||||||||||||
Attached Files | |||||||||||||||||||||||||||||||||||||||||
Bug heat | 254 | ||||||||||||||||||||||||||||||||||||||||
Complete LimeSurvey version number (& build) | 6.10.5 | ||||||||||||||||||||||||||||||||||||||||
I will donate to the project if issue is resolved | Yes | ||||||||||||||||||||||||||||||||||||||||
Browser | FF 138.0.4 (aarch64) | ||||||||||||||||||||||||||||||||||||||||
Database type & version | Maria DB 11.4 | ||||||||||||||||||||||||||||||||||||||||
Server OS (if known) | Ubuntu 22 | ||||||||||||||||||||||||||||||||||||||||
Webserver software & version (if known) | Apache/2.4.62 (Debian) | ||||||||||||||||||||||||||||||||||||||||
PHP Version | 8.3.17 | ||||||||||||||||||||||||||||||||||||||||
We are currently implementing LimeSurvey for our training measures, but the penetration test failed due to CVEs and EoLs. We are very interested in closing the security gaps and can also support with an assignment. Please contact me if interested via my user e-mail address |
|
We use our own kcfinder currently. I think this CVE are fixed currently. But right : can have other. |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2025-05-27 07:23 | manfredsteger | New Issue | |
2025-05-27 07:23 | manfredsteger | File Added: cves.png | |
2025-05-27 07:26 | manfredsteger | Note Added: 82766 | |
2025-05-27 07:26 | manfredsteger | Bug heat | 250 => 252 |
2025-05-27 08:49 | DenisChenu | Note Added: 82767 | |
2025-05-27 08:49 | DenisChenu | Bug heat | 252 => 254 |