CVE-2012-4994: Limesurvey
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.
Affected products
- Limesurvey Limesurvey: up to and including 1.91\+; version 1.01 only; version 1.50 only; version 1.52 only; version 1.53+ only; version 1.70+ only; …
Published 2012-09-19. Last modified 2026-06-16.