CVE-2019-9960 is a critical path traversal vulnerability affecting LimeSurvey through version 3.16.1+190225, specifically within the downloadZip function in application/controllers/admin/export.php. This flaw allows an unauthenticated attacker to exploit a relative path, leading to a CVSSv3 score of 9.8, indicating high impact on confidentiality, integrity, and availability with low attack complexity. While not listed on the KEV catalog, a Metasploit module exists for this vulnerability, suggesting readily available exploit code. Despite its severity and exploit availability, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.16.1\+190225CPE matchmatch criteria | cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.