Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-24506

Description

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.

POC

Reference

- https://bugs.limesurvey.org/bug_relationship_graph.php?bug_id=19364&graph=relation

- https://www.exploit-db.com/exploits/51926

Github

No PoCs found on GitHub currently.