{ "id": "CVE-2023-44796", "sourceIdentifier": "cve@mitre.org", "published": "2023-11-18T00:15:07.133", "lastModified": "2023-11-18T04:19:44.183", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component." } ], "metrics": {}, "references": [ { "url": "https://github.com/Hebing123/CVE-2023-44796/issues/1", "source": "cve@mitre.org" }, { "url": "https://github.com/LimeSurvey/LimeSurvey/pull/3483", "source": "cve@mitre.org" }, { "url": "https://github.com/limesurvey/limesurvey/commit/135511073c51c332613dd7fad9a8ca0aad34a3fe", "source": "cve@mitre.org" } ] }