cve/2024/CVE-2024-28710.md
2025-09-29 21:09:30 +02:00

682 B

CVE-2024-28710

Description

Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding in the Alert Widget's message component.

POC

Reference

No PoCs from references.

Github