In Limesurvey before 3.17.14, the entire database is exposed through browser caching.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released | release notes vendor advisory |
https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R53 | release notes third party advisory patch |