Security Advisory

CVE-2015-4628

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-06-18 10:00:00
Last updated 2024-08-06 06:18:12
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.