CVE-2020-25797

Source
https://cve.org/CVERecord?id=CVE-2020-25797
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25797.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-25797
Aliases
Published
2020-12-31T18:15:13.030Z
Modified
2026-07-08T19:02:48.483005Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Add Participants Function (First and last name parameters). When the survey participant being edited, e.g. by an administrative user, the JavaScript code will be executed in the browser.

References

Affected packages

Git / github.com/limesurvey/limesurvey

Affected ranges

Type
GIT
Repo
https://github.com/limesurvey/limesurvey
Events
Database specific
{
    "cpe": "cpe:2.3:a:limesurvey:limesurvey:3.21.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.21.1"
        },
        {
            "last_affected": "3.21.1"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.21.1
3.21.1+191210
3.21.2+191216

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25797.json"