Medium severity5.4NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026
CVE-2019-16173
CVE-2019-16173
Description
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
limesurvey/limesurveyPackagist | < 3.17.14 | 3.17.14 |
Affected products
3- LimeSurvey/LimeSurveydescription
Patches
Vulnerability mechanics
References
7- github.com/LimeSurvey/LimeSurvey/commit/f1c1ad2d24eb262363511fcca2e96ce737064006nvdPatchWEB
- packetstormsecurity.com/files/154479/LimeSurvey-3.17.13-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2019/Sep/22nvdExploitMailing ListThird Party AdvisoryWEB
- seclists.org/bugtraq/2019/Sep/27nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-r5f2-4wf4-cv66ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-16173ghsaADVISORY
- www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-releasednvdBroken LinkWEB
News mentions
0No linked articles in our index yet.