CVE-2012-4995
Published Sep 19, 2012
Last updated 7 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A4E67A9-B5CE-488F-8784-32A0A7A3E3C8", "versionEndIncluding": "1.91\\+" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.01:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8DFE81A-F6D7-4DA1-B499-3B4723958573" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.50:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBAF6BE3-CE45-4BF2-80FF-8A936FD14003" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.52:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FEA28520-E888-4A29-8D02-E63E810C7683" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.53\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1D35C89-7D5F-4BD8-AB43-EDE4C46B1D0F" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.70\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8F8E597-CF9C-4C87-A25D-9F71B5C33049" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.71\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47EA34BC-8D5D-4EAA-A712-EF85BD82D6E6" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.72:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB236E18-BAE3-4373-A60D-1D677C39F5FA" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.80\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97967070-D35E-4F10-A86A-12F9CF284ED3" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.81\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC4D779A-A8AE-4170-8FAF-B443AD431D7F" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.82\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB6D5422-82CA-4C23-8886-599E83084ED8" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.85:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEE66FF4-26D1-48C2-990B-0A22118A2ED4" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.86:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AB70332-D625-4CF6-9BEE-9E40BE971200" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.87\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CDD3DF1-50AB-4E63-AB02-A52139DE8768" }, { "criteria": "cpe:2.3:a:limesurvey:limesurvey:1.90\\+:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25651155-C569-45AC-8E9D-9AE4E6C68FC1" } ], "operator": "OR" } ] } ]