The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| limesurvey/limesurvey(Packagist) | 0 | 3.27.19 | N/A |
CVSS Metrics