← back
CVE-2019-9960

CVE-2019-9960

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 13%
from disclosure to weapon375 days
Published on NVDMar 24
metasploit+375d
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
Affected products
n/a · n/a