CyberRota Analysis
AI-GeneratedAuthenticated users of LimeSurvey Community Edition 7.3.0 can exploit a vulnerability that allows them to manipulate survey data by using identifiers from other users' surveys without proper authorization checks. This could lead to unauthorized access and modification of sensitive survey information, potentially compromising data integrity. Organizations using this version of LimeSurvey should prioritize patching this vulnerability to protect against potential data breaches and unauthorized survey manipulation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.