LimeSurvey 5.2.4 contains a Remote Code Execution vulnerability in the plugin upload and install functionality. A remote attacker with superadmin privileges can upload a plugin containing arbitrary PHP code, which will be executed by the application. The vendor asserts that this is by design, as only superadmins can install plugins and plugins are expected to contain PHP code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, self-contained authenticated RCE exploit for LimeSurvey CVE-2021-44967. It contains four files: a README with usage guidance, exploit.py as the main automation script, php-rev.php as the payload, and config.xml as the required LimeSurvey plugin manifest. The exploit flow in exploit.py is straightforward and operational: it accepts a target base URL, username, and password; creates a ZIP archive named upload_me.zip containing php-rev.php and config.xml; starts a requests session; retrieves a CSRF token from the LimeSurvey login page; authenticates with supplied credentials; accesses the plugin manager; uploads the ZIP as a plugin; confirms upload; installs the uploaded plugin; enumerates plugin rows in the plugin manager HTML to find the plugin named Y1LD1R1M and extract its pluginId; activates the plugin; and finally triggers code execution by requesting the uploaded PHP file directly from /upload/plugins/Y1LD1R1M/php-rev.php. The payload php-rev.php is a classic PHP reverse shell. It is hardcoded to connect back to 10.10.14.84 on TCP port 443, then launches 'uname -a; w; id; /bin/sh -i' via proc_open and relays shell I/O over the socket. This gives the operator interactive command execution on the target host in the context of the web server/PHP process. Because the callback IP and port are hardcoded and intended to be edited manually, the exploit is best classified as OPERATIONAL rather than weaponized. The repository does not appear to be part of a larger exploit framework. It is a real exploit rather than a detector: it performs authenticated abuse of LimeSurvey's plugin upload/install/activation workflow to achieve remote code execution. The main attack vector is web-based authenticated exploitation of the administrative interface, followed by network-based reverse shell callback from the victim to the attacker.
This repository contains a working exploit for CVE-2021-44967, targeting LimeSurvey version 5.2.4. The exploit is implemented in Python (exploit.py) and requires valid superadmin credentials for the LimeSurvey admin panel. The script automates the process of generating a malicious plugin containing a PHP reverse shell, zipping it with a crafted config.xml, and uploading it via the plugin manager endpoints. After uploading, the script installs and activates the plugin, then triggers the PHP reverse shell by accessing it directly. The attacker must supply their own host and port for the reverse shell connection. The exploit demonstrates a full remote code execution chain, leveraging authenticated plugin upload and execution functionality. The repository is structured with a README.md providing usage instructions and exploit.py containing the exploit logic. No detection or scanning functionality is present; this is a direct exploitation tool.
This repository contains a Python proof-of-concept exploit for CVE-2021-44967, a remote code execution vulnerability in LimeSurvey (tested on version 6.6.4, but claims compatibility with 3.x-7.x). The exploit works by authenticating as an administrator, uploading a malicious plugin (containing a PHP reverse shell), activating the plugin, and then triggering the payload to obtain a reverse shell on the attacker's machine. The main script, 'limesurvey_rce.py', is well-structured and automates the entire attack chain, including authentication, CSRF token handling, plugin packaging (with config.xml and payload.php), and reverse shell setup. The payload defaults to a modified version of pentestmonkey's php-reverse-shell.php, but a custom PHP payload can be supplied. The exploit requires valid admin credentials and network access to the LimeSurvey web interface. The README provides usage instructions, options, and an example run. No detection or fake code is present; this is a functional exploit.
This repository contains an operational exploit for CVE-2021-44967, targeting LimeSurvey version 5.2.x. The main file, CVE-2021-44967.py, is a Python script that automates the process of authenticating to a LimeSurvey instance, uploading a malicious plugin (packaged as a ZIP containing a PHP reverse shell and a config.xml), installing and activating the plugin, and finally triggering the reverse shell. The exploit requires valid credentials for a user with plugin upload permissions. The payload is a PHP reverse shell that connects back to the attacker's specified host and port, granting remote code execution. The repository also includes a README.md with usage instructions and references, and a LICENSE file. The exploit interacts with several LimeSurvey admin endpoints, including login, plugin upload, install, and activation, and ultimately places the webshell at a predictable URL under /upload/plugins/<plugin_name>/php-rev.php.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.