[Git][security-tracker-team/security-tracker][master] new limesurvey issues
Moritz Muehlenhoff
jmm at debian.org
Tue Sep 10 09:22:38 BST 2019
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b0f9b47d by Moritz Muehlenhoff at 2019-09-10T08:22:18Z
new limesurvey issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -57,33 +57,33 @@ CVE-2017-18597
CVE-2017-18596
RESERVED
CVE-2019-16187 (Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnl ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16186 (In Limesurvey before 3.17.14, admin users can access the plugin manage ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16185 (In Limesurvey before 3.17.14, admin users can view, update, or delete ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16184 (A CSV injection vulnerability was found in Limesurvey before 3.17.14 t ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16183 (In Limesurvey before 3.17.14, admin users can run an integrity check w ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16182 (A reflected cross-site scripting (XSS) vulnerability was found in Lime ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16181 (In Limesurvey before 3.17.14, admin users can mark other users' notifi ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16180 (Limesurvey before 3.17.14 allows remote attackers to bruteforce the lo ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16179 (Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the defaul ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16178 (A stored cross-site scripting (XSS) vulnerability was found in Limesur ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16177 (In Limesurvey before 3.17.14, the entire database is exposed through b ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16176 (A path disclosure vulnerability was found in Limesurvey before 3.17.14 ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16175 (A clickjacking vulnerability was found in Limesurvey before 3.17.14. ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16174 (An XML injection vulnerability was found in Limesurvey before 3.17.14 ...)
- TODO: check
+ - limesurvey <itp> (bug #472802)
CVE-2019-16173 (LimeSurvey before v3.17.14 allows reflected XSS for escalating privile ...)
- limesurvey <itp> (bug #472802)
CVE-2019-16172 (LimeSurvey before v3.17.14 allows stored XSS for escalating privileges ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/b0f9b47db4de5e540aba9b189c4e5ace12724ae6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/b0f9b47db4de5e540aba9b189c4e5ace12724ae6
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20190910/b271b91b/attachment.html>
More information about the debian-security-tracker-commits
mailing list