Description
LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.
Remediation
References
Related Vulnerabilities
WordPress Plugin DELUCKS SEO Cross-Site Scripting (2.1.7)
WebLogic Other Vulnerability (CVE-2020-10672)
MySQL CVE-2019-2581 Vulnerability (CVE-2019-2581)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk Cross-Site Scripting (5.127.3)
WordPress Plugin Localize My Post Local File Inclusion (1.0)