CVE-2024-39063

Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-07-09 20:15

Updated : 2024-07-11 13:06


NVD link : CVE-2024-39063

Mitre link : CVE-2024-39063

CVE.ORG link : CVE-2024-39063


JSON object : View

Products Affected

No product.

CWE

No CWE.