CVE-2018-1000053
Summary
| CVE | CVE-2018-1000053 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-09 23:29:00 UTC |
| Updated | 2018-03-08 15:23:00 UTC |
| Description | LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear to be exploitable via Simple HTML markup can be used to send a GET request to the affected endpoint. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Limesurvey | Limesurvey | 3.0.0 | beta3 | All | All |
| Application | Limesurvey | Limesurvey | 3.0.0 | beta3 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fixed issue: no CRSF check for uninstall theme, reported by MUSTAFA H… · LimeSurvey/LimeSurvey@1e44020 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.