{"id":"CVE-2020-11455","aliases":["BIT-limesurvey-2020-11455"],"url":"https://o3.security/vulnerability/CVE-2020-11455","summary":null,"details":"LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.","published":"2020-04-01T16:15:27.420Z","modified":"2026-08-07T15:11:34.646339Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.97179,"percentile":0.99889,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":4,"affectedPackages":[],"fix":{"url":"https://github.com/LimeSurvey/LimeSurvey/commit/daf50ebb16574badfb7ae0b8526ddc5871378f1b","label":"LimeSurvey/LimeSurvey@daf50eb"},"references":[{"type":"FIX","url":"https://github.com/LimeSurvey/LimeSurvey/commit/daf50ebb16574badfb7ae0b8526ddc5871378f1b"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/157112/LimeSurvey-4.1.11-Path-Traversal.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/48297"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:11:34.646339Z"}}