LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.
{
    "cpes": [
        "cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:limesurvey:limesurvey:4.1.12:-:*:*:*:*:*:*",
        "cpe:2.3:a:limesurvey:limesurvey:4.1.12:200324:*:*:*:*:*:*"
    ],
    "severity": "Critical"
}