Vulnerability record · CVE-2020-11455 · published 1 April 2020
CVE-2020-11455: LimeSurvey file manager path traversal
Limesurvey · Limesurvey
LimeSurvey before 4.1.12+200324 contains a path traversal flaw in application/controllers/admin/LimeSurveyFileManager.php. An unauthenticated remote attacker can manipulate file paths, which matters because the file manager is reachable without credentials and the flaw carries a critical CVSS score.
Description
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and near-maximum EPSS make this an urgent exposure.
What it is
LimeSurvey before 4.1.12+200324 contains a path traversal flaw in application/controllers/admin/LimeSurveyFileManager.php. An unauthenticated remote attacker can manipulate file paths, which matters because the file manager is reachable without credentials and the flaw carries a critical CVSS score.
Impact
An attacker can read and write files outside the intended directory, potentially leading to code execution or full compromise of the LimeSurvey host.
Attack surface
Reached over the network through the admin file manager controller; the CVSS vector shows no privileges or user interaction required.
Exploitation
Public exploit code exists in Packet Storm and Exploit-DB, and EPSS is 0.97179 (99.9th percentile), though CISA KEV does not list it.
What to do
- Upgrade LimeSurvey to 4.1.12+200324 or later, applying commit daf50ebb16574badfb7ae0b8526ddc5871378f1b.
- Restrict network access to the admin file manager endpoints to trusted management networks.
- Enforce strict path canonicalization and reject traversal sequences in file manager inputs.
- Run the web service with least privilege and confine its file access to the required directories.
Detection
- Monitor web logs for traversal sequences such as ../ or encoded variants against LimeSurvey file manager paths.
- Alert on file reads or writes outside the expected LimeSurvey upload and application directories.
- Watch for requests to application/controllers/admin/LimeSurveyFileManager.php from unexpected source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157112/LimeSurvey-4.1.11-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/LimeSurvey/LimeSurvey/commit/daf50ebb16574badfb7ae0b8526ddc5871378f1b | PatchThird Party Advisory |
| https://www.exploit-db.com/exploits/48297 | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/157112/LimeSurvey-4.1.11-Path-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/LimeSurvey/LimeSurvey/commit/daf50ebb16574badfb7ae0b8526ddc5871378f1b | PatchThird Party Advisory |
| https://www.exploit-db.com/exploits/48297 | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2020-11455 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11455), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.