In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released | release notes vendor advisory |
https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R51 | release notes third party advisory patch |