Store XSS in Survey menus in limesurvey/limesurvey

Valid

Reported on

Sep 3rd 2023


Description

I noticed, your website is very secure.

But you overlooked a flaw Store DOM XSS .

Proof of Concept

Detail:

1 .Login vs admin demo account and access Configuration

2 .Go to Survey menus ==> Survey menus entries

3 .Add new menu entry and insert payload in to GET data method

test<script>alert(document.domain)</script>

4 .Click create ==> detect XSS

Video Poc

https://drive.google.com/file/d/1VWRE5GNGJGDc6HES0tLG3PIHMRgfOIOj/view?usp=sharing

Impact

This security vulnerability has the potential to steal multiple users' cookies, gain unauthorized access to that user's account through stolen cookies, or redirect the user to other malicious websites...

We are processing your report and will contact the limesurvey team within 24 hours. 3 months ago
We have contacted a member of the limesurvey team and are waiting to hear back 3 months ago
HaiNguyen modified the report
3 months ago
HaiNguyen
2 months ago

Researcher


@mantainer? any update on this?

HaiNguyen modified the report
2 months ago
HaiNguyen
2 months ago

Researcher


hi, any update for this?

HaiNguyen modified the report
2 months ago
HaiNguyen
2 months ago

Researcher


Hi , any updates?

HaiNguyen modified the report
2 months ago
HaiNguyen
2 months ago

Researcher


I have submitted the second report. When you reply, I will close the report. Sorry for this problem. Thank you.

tiborpacalat
2 months ago

Maintainer


Internal tracking number: 19114

HaiNguyen
2 months ago

Researcher


Hi, any new update ?

HaiNguyen
2 months ago

Researcher


Hi, any new update ?

tiborpacalat validated this vulnerability 2 months ago
HaiNguyen has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
HaiNguyen
a month ago

Researcher


Hi, vulnerability has been fixed, is there any new update?

tiborpacalat marked this as fixed in 6.3.1+231023 with commit d3fb27 a month ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
tiborpacalat published this vulnerability a month ago
to join this conversation