Medium severity5.4NVD Advisory· Published Nov 17, 2020· Updated Jun 17, 2026
CVE-2020-25798
CVE-2020-25798
Description
A stored cross-site scripting (XSS) vulnerability in LimeSurvey before and including 3.21.1 allows authenticated users with correct permissions to inject arbitrary web script or HTML via parameter ParticipantAttributeNamesDropdown of the Attributes on the central participant database page. When the survey attribute being edited or viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*range: <=3.21.1
- (no CPE)
- (no CPE)range: <=3.21.1
Patches
Vulnerability mechanics
References
2- github.com/LimeSurvey/LimeSurvey/commit/38e1ab069b538de7cb5f3a04939aba8e835640cbnvdPatchThird Party Advisory
- bugs.limesurvey.org/view.phpnvdExploitIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.