A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 20 Feb 2025 03:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding. | 
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2022-02-22T21:17:32.000Z
Updated: 2025-02-20T03:12:37.814Z
Reserved: 2021-12-13T00:00:00.000Z
Link: CVE-2021-44967
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2022-02-24T15:15:24.547
Modified: 2025-02-20T03:15:11.197
Link: CVE-2021-44967
 Redhat
                        Redhat
                    No data.