Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP authentication method is used.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Limesurvey |
Limesurvey |
* |
3.17.14 (excluding) |
References