In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/LimeSurvey/LimeSurvey/blob/3be9b41e76826b57f5860d18d93b23f47d59d2e4/docs/release_notes.txt#L51 | third party advisory |