← Vulnerability feed

Vulnerability record · CVE-2020-11455 · published 1 April 2020

CVE-2020-11455: LimeSurvey file manager path traversal

Limesurvey · Limesurvey

LimeSurvey before 4.1.12+200324 contains a path traversal flaw in application/controllers/admin/LimeSurveyFileManager.php. An unauthenticated remote attacker can manipulate file paths, which matters because the file manager is reachable without credentials and the flaw carries a critical CVSS score.

9.8 CVSS 3.1 Critical EPSS 97% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and near-maximum EPSS make this an urgent exposure.

What it is

LimeSurvey before 4.1.12+200324 contains a path traversal flaw in application/controllers/admin/LimeSurveyFileManager.php. An unauthenticated remote attacker can manipulate file paths, which matters because the file manager is reachable without credentials and the flaw carries a critical CVSS score.

Impact

An attacker can read and write files outside the intended directory, potentially leading to code execution or full compromise of the LimeSurvey host.

Attack surface

Reached over the network through the admin file manager controller; the CVSS vector shows no privileges or user interaction required.

Exploitation

Public exploit code exists in Packet Storm and Exploit-DB, and EPSS is 0.97179 (99.9th percentile), though CISA KEV does not list it.

What to do

  • Upgrade LimeSurvey to 4.1.12+200324 or later, applying commit daf50ebb16574badfb7ae0b8526ddc5871378f1b.
  • Restrict network access to the admin file manager endpoints to trusted management networks.
  • Enforce strict path canonicalization and reject traversal sequences in file manager inputs.
  • Run the web service with least privilege and confine its file access to the required directories.

Detection

  • Monitor web logs for traversal sequences such as ../ or encoded variants against LimeSurvey file manager paths.
  • Alert on file reads or writes outside the expected LimeSurvey upload and application directories.
  • Watch for requests to application/controllers/admin/LimeSurveyFileManager.php from unexpected source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11455 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-56422Limesurvey deserialization of untrusted data vulnerabilityA deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.EPSS 0.85%9.8CVE-2022-48008Limesurvey unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.EPSS 1.3%9.8CVE-2019-25019Limesurvey sql injection vulnerabilityLimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.EPSS 1.3%9.8CVE-2019-16184Limesurvey csv injection vulnerabilityA CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands via their survey responses th…EPSS 1.7%9.8CVE-2019-9960Limesurvey path traversal vulnerabilityThe downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.EPSS 13%9.8CVE-2018-17057Tecnick tcpdf deserialization of untrusted data vulnerabilityAn issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.EPSS 26%9.3CVE-2025-41375Limesurvey sql injection vulnerabilitySQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via '…EPSS 0.63%9.3CVE-2008-2570Limesurvey vulnerabilityMultiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2020-11455), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.