CVE-2024-6933 | LimeSurvey 6.5.14-240624 Survey General Settings updatesurveylocalesettings_generalsettings actionUpdateSurveyLocaleSettingsGeneralSettings Language sql injection
A vulnerability identified as critical has been detected in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file /index.php?r=admin/database/index/updatesurveylocalesettings_generalsettings of the component Survey General Settings Handler. This manipulation of the argument Language causes sql injection.
This vulnerability is tracked as CVE-2024-6933. The attack is possible to be carried out remotely. Moreover, an exploit is present.
You should upgrade the affected component.