PT-2024-30195 · Unknown · Limesurvey

·

CVE-2024-42901

·

Published

2024-09-03

·

Updated

2025-07-04

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lime Survey version 6.5.12
Description A CSV injection issue allows attackers to execute arbitrary code by uploading a specially crafted CSV file.
Recommendations For Lime Survey version 6.5.12, update to a version that fixes this issue to prevent arbitrary code execution via crafted CSV files.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-LIMESURVEY-2024-42901
CVE-2024-42901

Affected Products

Limesurvey