{"id":"CVE-2021-44967","details":"A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.","aliases":["BIT-limesurvey-2021-44967"],"modified":"2026-08-07T17:03:13.018100Z","published":"2022-02-24T15:15:24.547Z","references":[{"type":"WEB","url":"https://www.limesurvey.org/manual/Plugins_-_advanced"},{"type":"EVIDENCE","url":"https://github.com/Y1LD1R1M-1337/Limesurvey-RCE"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/50573"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/limesurvey/limesurvey","events":[{"introduced":"66868d6887d153c81b50fec957390fd70b434014"},{"last_affected":"66868d6887d153c81b50fec957390fd70b434014"}],"database_specific":{"cpe":"cpe:2.3:a:limesurvey:limesurvey:5.2.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.2.4"},{"last_affected":"5.2.4"}],"source":"CPE_STRING"}}],"versions":["5.2.4","5.2.4+211129"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44967.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}