A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/50573 | exploit vdb entry third party advisory |
https://github.com/Y1LD1R1M-1337/Limesurvey-RCE | third party advisory exploit |
https://www.limesurvey.org/manual/Plugins_-_advanced |