Host Header Injection in LimeSurvey Password Reset Function
CVE-2024-42903

6.5MEDIUM

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
3 September 2024

What is CVE-2024-42903?

A host header injection flaw in the password reset functionality of LimeSurvey creates a risk for users. When exploiting this vulnerability, attackers can manipulate the host header and deceive users into clicking on malicious password reset links. This might lead users to unsafe domains, potentially compromising their sensitive information. All versions prior to v.6.6.1+240806 are susceptible to this threat, making immediate attention to updates critical for users to safeguard against potential phishing attacks.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.