Description
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
Remediation
References
Related Vulnerabilities
WordPress 4.3.x Arbitrary File Deletion Vulnerability (4.3 - 4.3.16)
Apache HTTP Server CVE-2007-3304 Vulnerability (CVE-2007-3304)
WordPress Plugin WPZOOM Portfolio Cross-Site Scripting (1.2.1)
Plone CMS Improper Input Validation Vulnerability (CVE-2015-7318)
Drupal Improper Input Validation Vulnerability (CVE-2019-6339)