Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.152904
Categoría:Denial of Service
Título:LimeSurvey < 6.3.0 DoS Vulnerability
Resumen:LimeSurvey is prone to a denial of service (DoS); vulnerability.
Descripción:Summary:
LimeSurvey is prone to a denial of service (DoS)
vulnerability.

Vulnerability Insight:
The vulnerability is associated with surveys published by
administrators that include the 'file upload' option. During the survey submission process, users
can upload files, and the system validates the size of uploaded files. However, proper input
validation is not performed on the uploaded file size, enabling attackers to manipulate submitted
data to bypass the expected handling of the system.

Specifically, attackers can manipulate the submitted data and set the 'size' parameter to a
non-integer value, such as a string. Due to the lack of appropriate input validation, the system
fails to handle this non-integer value correctly, resulting in an error. This error renders
administrators unable to access statistical results for the affected survey, as the system fails
to correctly parse the input data.

Affected Software/OS:
LimeSurvey prior to version 6.3.0.

Solution:
Update to version 6.3.0 or later.

CVSS Score:
3.3

CVSS Vector:
AV:N/AC:L/Au:M/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2024-7887
CopyrightCopyright (C) 2024 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.