← Back to CVE List

CVE-2021-44967

Published: 2022-02-24T15:15Z
Last Modified: 2025-02-20T03:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt