CVE-2021-44967
A vulnerability classified as critical has been found in LimeSurvey 5.2.4 (Survey Software). Affected is an unknown code of the component Plugin Handler. The manipulation with an unknown input leads to a unrestricted upload vulnerability. CWE is classifying the issue as CWE-434. The product allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product’s environment. This is going to have an impact on confidentiality, integrity, and availability.
Exploit
Exploit found online
The exploit requires modifications