### [CVE-2024-24506](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24506) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function. ### POC #### Reference - https://bugs.limesurvey.org/bug_relationship_graph.php?bug_id=19364&graph=relation - https://www.exploit-db.com/exploits/51926 #### Github No PoCs found on GitHub currently.