Vulnerability CVE-2024-28710


Published: 2024-10-07

Description:
Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.

 References:
http://limesurvey.com
https://github.com/LimeSurvey/LimeSurvey/commit/c2fd60f94bc1db275f20cbb27a3135a9bdfb7f10

Copyright 2026, cxsecurity.com

 

Back to Top