Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2017-18358

Description

LimeSurvey before 2.72.4 has Stored XSS by using the Continue Later (aka Resume later) feature to enter an email address, which is mishandled in the admin panel.

POC

Reference

- https://blog.ripstech.com/2018/limesurvey-persistent-xss-to-code-execution/

Github

No PoCs found on GitHub currently.