An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer identifiers belonging to another user's survey. The REST survey-patching endpoint checks the attacker's permission against the survey ID in the request URL, but the vulnerable persistence operations resolve the target object independently by its global qid or aid and never verify that it belongs to that authorized survey. | |
| Title | LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations | |
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:linux:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:macos:*:*:*:*:* cpe:2.3:a:limesurvey:limesurvey:7.3.0:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2026-09-29T02:20:43.077Z
Reserved: 2026-09-24T21:11:19.206Z
Link: CVE-2026-97685
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses