CVE-2024-6933
Last modified
CVE-2024-6933 is a low-severity vulnerability rated 2.1/10 on the CVSS scale. A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. This manipulation of the argument Language causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 6.6.2+240827 can resolve this issue. Patch name: d656d2c7980b7642560977f4780e64533a68e13d. You should upgrade the affected component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Limesurvey | Limesurvey | >= 6.5.14, < 6.6.2 |
References
- https://github.com/Hebing123/cve/issues/55Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.271988Permissions Required, VDB Entry
- https://vuldb.com/?id.271988Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.372007Third Party Advisory, VDB Entry
- https://github.com/Hebing123/cve/issues/55Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.271988Permissions Required, VDB Entry
- https://vuldb.com/?id.271988Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.372007Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6933?
How severe is CVE-2024-6933?
How do I fix CVE-2024-6933?
Are you affected by CVE-2024-6933?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
