CVE-2025-34120 is an unauthenticated arbitrary file download vulnerability affecting LimeSurvey versions from 2.0+ through 2.06+ Build 151014. The issue is present in the admin backup endpoint at index.php/admin/update/sa/backup, where the application does not properly validate serialized input supplied via the datasupdateinfo parameter. By crafting this payload, an attacker can influence file path selection and cause the application to include arbitrary files from the underlying host in a generated ZIP archive. The archive is then made available for download without authentication, enabling remote read access to files outside the intended backup scope, including operating system files and application configuration data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
index.php/admin/update/sa/backup, especially from untrusted networks. Place the application behind network access controls, a reverse proxy, or VPN to limit reachability. Implement web application firewall rules or custom request filtering to block requests containing crafted or unexpected datasupdateinfo input, particularly serialized payloads and path traversal-style file references. Minimize the impact of disclosure by ensuring sensitive files are not readable by the web application process beyond what is strictly necessary, and store secrets outside web-accessible or application-readable locations where feasible.Patch, then assume compromise.
index.php/admin/update/sa/backup. Rotate any credentials or secrets that may have been exposed through arbitrary file disclosure.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module that exploits an unauthenticated file download vulnerability in LimeSurvey versions 2.0+ to 2.06+ Build 151014 (CVE-2025-34120). The module sends a crafted POST request to the vulnerable admin update backup endpoint, leveraging a file traversal vulnerability to download arbitrary files from the server. The files are returned as ZIP archives, which the module automatically extracts and saves. The default target file is /etc/passwd, but any file path can be specified. The exploit does not require authentication and is operational, providing a practical method for attackers to exfiltrate sensitive files from vulnerable LimeSurvey installations. The code is written in Ruby and is designed to be used within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.