Medium severity6.1NVD Advisory· Published Aug 5, 2020· Updated Jun 17, 2026
CVE-2020-16192
CVE-2020-16192
Description
LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.
Affected products
4<4.3.2+ 2 more
- (no CPE)range: <4.3.2
- (no CPE)
- cpe:2.3:a:limesurvey:limesurvey:4.3.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/LimeSurvey/LimeSurvey/pull/1479/commits/4109a8d157e46c48ca34b995ef61a6e0f6905236nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.