[Git][security-tracker-team/security-tracker][master] new limesurvey issues

Moritz Muehlenhoff jmm at debian.org
Tue Sep 10 09:22:38 BST 2019



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b0f9b47d by Moritz Muehlenhoff at 2019-09-10T08:22:18Z
new limesurvey issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -57,33 +57,33 @@ CVE-2017-18597
 CVE-2017-18596
 	RESERVED
 CVE-2019-16187 (Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnl ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16186 (In Limesurvey before 3.17.14, admin users can access the plugin manage ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16185 (In Limesurvey before 3.17.14, admin users can view, update, or delete  ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16184 (A CSV injection vulnerability was found in Limesurvey before 3.17.14 t ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16183 (In Limesurvey before 3.17.14, admin users can run an integrity check w ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16182 (A reflected cross-site scripting (XSS) vulnerability was found in Lime ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16181 (In Limesurvey before 3.17.14, admin users can mark other users' notifi ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16180 (Limesurvey before 3.17.14 allows remote attackers to bruteforce the lo ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16179 (Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the defaul ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16178 (A stored cross-site scripting (XSS) vulnerability was found in Limesur ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16177 (In Limesurvey before 3.17.14, the entire database is exposed through b ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16176 (A path disclosure vulnerability was found in Limesurvey before 3.17.14 ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16175 (A clickjacking vulnerability was found in Limesurvey before 3.17.14. ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16174 (An XML injection vulnerability was found in Limesurvey before 3.17.14  ...)
-	TODO: check
+	- limesurvey <itp> (bug #472802)
 CVE-2019-16173 (LimeSurvey before v3.17.14 allows reflected XSS for escalating privile ...)
 	- limesurvey <itp> (bug #472802)
 CVE-2019-16172 (LimeSurvey before v3.17.14 allows stored XSS for escalating privileges ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/b0f9b47db4de5e540aba9b189c4e5ace12724ae6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/b0f9b47db4de5e540aba9b189c4e5ace12724ae6
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190910/b271b91b/attachment.html>


More information about the debian-security-tracker-commits mailing list