CVE-2019-16184 (NVD)

2019-09-09

A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses that will be included in the export CSV file.

Products Limesurvey
Type Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (CWE-74)
First patch - None (likely due to unavailable code)
Links https://github.com/LimeSurvey/LimeSurvey/commit/5870fd1037058bc4e43cccf893b576c72293371e#diff-d539f3f8185667ee48db78e1bf65a3b4R46
https://www.limesurvey.org/limesurvey-updates/2188-limesurvey-3-17-14-build-190902-released