CVE-2021-44967


A vulnerability classified as critical has been found in LimeSurvey 5.2.4 (Survey Software). Affected is an unknown code of the component Plugin Handler. The manipulation with an unknown input leads to a unrestricted upload vulnerability. CWE is classifying the issue as CWE-434. The product allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product’s environment. This is going to have an impact on confidentiality, integrity, and availability.

Exploit


Exploit found online The exploit requires modifications