Medium severity5.4NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026
CVE-2019-16172
CVE-2019-16172
Description
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
limesurvey/limesurveyPackagist | < 3.17.14 | 3.17.14 |
Affected products
3- LimeSurvey/LimeSurveydescription
Patches
Vulnerability mechanics
References
7- github.com/LimeSurvey/LimeSurvey/commit/32d6a5224327b246ee3a2a08500544e4f80f9a9anvdPatchWEB
- packetstormsecurity.com/files/154479/LimeSurvey-3.17.13-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2019/Sep/22nvdExploitMailing ListThird Party AdvisoryWEB
- seclists.org/bugtraq/2019/Sep/27nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-fr47-r224-c36mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-16172ghsaADVISORY
- www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-releasednvdBroken LinkWEB
News mentions
0No linked articles in our index yet.