CVE-2024-42903
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
03/09/2024
Last modified:
13/03/2025
Description
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:* | 6.6.1\+240806 (including) |
To consult the complete list of CPE names with products and versions, see this page



