View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update | ||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
20125 | Bug reports | Security | public | 2025-05-27 07:23 | 2025-06-25 06:44 | ||||||||||||||||||||||||||||||||||||
Reporter | manfredsteger | Assigned To | |||||||||||||||||||||||||||||||||||||||
Priority | none | Severity | partial_block | ||||||||||||||||||||||||||||||||||||||
Status | new | Resolution | open | ||||||||||||||||||||||||||||||||||||||
Product Version | 6.6.x | ||||||||||||||||||||||||||||||||||||||||
Summary | 20125: Third-party components affected by known vulnerabilities (CVEs) | ||||||||||||||||||||||||||||||||||||||||
Description | During a security review of LimeSurvey 6.10.x, several third-party components were identified that are outdated and affected by known vulnerabilities (CVEs). These components pose potential security risks and should be updated to their latest secure versions. The application uses the following software packages with known vulnerabilities:
� Recommended Actions
| ||||||||||||||||||||||||||||||||||||||||
Steps To Reproduce | OWASP Test and pentest-tools.com used | ||||||||||||||||||||||||||||||||||||||||
Tags | No tags attached. | ||||||||||||||||||||||||||||||||||||||||
Attached Files | |||||||||||||||||||||||||||||||||||||||||
Bug heat | 262 | ||||||||||||||||||||||||||||||||||||||||
Complete LimeSurvey version number (& build) | 6.10.5 | ||||||||||||||||||||||||||||||||||||||||
I will donate to the project if issue is resolved | Yes | ||||||||||||||||||||||||||||||||||||||||
Browser | FF 138.0.4 (aarch64) | ||||||||||||||||||||||||||||||||||||||||
Database type & version | Maria DB 11.4 | ||||||||||||||||||||||||||||||||||||||||
Server OS (if known) | Ubuntu 22 | ||||||||||||||||||||||||||||||||||||||||
Webserver software & version (if known) | Apache/2.4.62 (Debian) | ||||||||||||||||||||||||||||||||||||||||
PHP Version | 8.3.17 | ||||||||||||||||||||||||||||||||||||||||
We are currently implementing LimeSurvey for our training measures, but the penetration test failed due to CVEs and EoLs. We are very interested in closing the security gaps and can also support with an assignment. Please contact me if interested via my user e-mail address |
|
We use our own kcfinder currently. I think this CVE are fixed currently. But right : can have other. |
|
Is it possible that the mentioned components could be updated against remunation/payments to a stable version, and that abandoned projects would switch to an existing one? I'm not a LimeSurvey expert; I'm just a project manager. However, based on what I see, only the KCFinder is needed for the file upload process. As mentioned before, CKEditor could potentially handle this directly. To reiterate what I said earlier, removing EoL projects entirely would be in the community's interest. |
|
@manfredsteger, please note that all issues are referring to the admin interface only. That means only logged in Limesurvey admin users would be able to mis-use any of these security issues. |
|
@Mazi Yes, we’ve considered locking down the backend—and I suspect that nearly every university or educational institution with strict security measures will do exactly that. Personally, I think it’s fundamentally wrong: many IT teams go to the trouble of hiding everything behind VPNs, and users then have to overcome this hurdle, leading to constant support requests and frustration for inexperienced users. Our policy is to install everything properly and cleanly, without hiding anything behind firewalls or VPNs—that approach is old-school. Don’t you share the goal of making LimeSurvey inherently more secure—and getting paid for it? |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2025-05-27 07:23 | manfredsteger | New Issue | |
2025-05-27 07:23 | manfredsteger | File Added: cves.png | |
2025-05-27 07:26 | manfredsteger | Note Added: 82766 | |
2025-05-27 07:26 | manfredsteger | Bug heat | 250 => 252 |
2025-05-27 08:49 | DenisChenu | Note Added: 82767 | |
2025-05-27 08:49 | DenisChenu | Bug heat | 252 => 254 |
2025-06-05 13:20 | manfredsteger | Note Added: 82830 | |
2025-06-13 11:29 | Mazi | Note Added: 82878 | |
2025-06-13 11:29 | Mazi | Bug heat | 254 => 256 |
2025-06-13 11:29 | guest | Bug heat | 256 => 262 |
2025-06-25 06:44 | manfredsteger | Note Added: 82943 |