Check out the LimeSurvey source code on GitHub!

How safe is LimeSurvey?

More
4 years 1 month ago #90517 by Raptor
I am new to LimeSurvey. And this is my first encounter with the software.

First I have to admit that your job is very helpful to our college and community.

I am concerned about the security of the application and the possible attacks or backdoors that by installing this application on my server, it can cause for me. How can I be sure about the security of the software? What can I do to increase the security, as an admin?

Thank you for your help and I am only asking this because I found these on the net:

www.exploit-db.com/exploits/19330/
www.exploit-db.com/exploits/18508/
www.exploit-db.com/exploits/4544/
www.exploit-db.com/exploits/4156/

Thank you
And please keep up the good job.

Please Log in to join the conversation.

More
4 years 1 month ago #90525 by Fred01
That's a good question. Limesurvey is a lot like any "user generated content" application and users can try to exploit that. And because it's open source anyone can look under the hood and look for exploits

But then, anyone can also report problems to the developers also. I know they respond quickly to this stuff. Here's an example from the bugs site. Look around and you'll see others.
bugs.limesurvey.org/view.php?id=7105

There are some installation security hints in the manual. Most of this is typical Linux application security: docs.limesurvey.org/Installation+security+hints

BTW, most of those exploits you posted are ancient. :)
The following user(s) said Thank You: Raptor

Please Log in to join the conversation.

More
4 years 1 month ago #90528 by Mazi
Two of these issues are from 2007 so they are more than 5 years old. Another one refers to the old 1.91 version which isn't used that much and the latest issue is already fixed as well.

Anyway, if you find any further issues, please file a ticket at our Bugtracker and we will fix it as soon as possible.


Best regards/Beste Grüße,
Dr. Marcel Minke
(Limesurvey Head of Support)
Need Help? We offer professional Limesurvey support
Contact: marcel.minke(at)survey-consulting.com'"
The following user(s) said Thank You: Raptor

Please Log in to join the conversation.

More
4 years 2 weeks ago - 4 years 2 weeks ago #92073 by Raptor
I know. And thanks for calling them ancient not anything else... ;)
I just wanted to have a ruler to measure how sure I can be with my lovely LimeSurvey installation, that's all.
Last Edit: 4 years 2 weeks ago by Raptor. Reason: I forgot to mention sth

Please Log in to join the conversation.

More
4 years 2 weeks ago #92121 by lowprofile
If an exploit is discovered for pre 2.0 ..eg 1.92+ 120919 will there be any patches?

Please Log in to join the conversation.

More
4 years 2 weeks ago #92134 by c_schmitz
No, sorry.

Best regards

Carsten Schmitz
LimeSurvey project leader

Please Log in to join the conversation.

More
4 years 2 weeks ago #92259 by StuartMark0
On a similar note, what happens when I delete any survey post completion, does it deletes just the tables or everything from my server or Lime Survey's server? Is there any possibility that someone can sneak in later and get an access to the deleted surveys?(Survey script, Datafile, Tokens along with contact list)

Please Log in to join the conversation.

Imprint                   Privacy policy         General Terms & Conditions         Revocation information and revocation form