CVE-2024-42903

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
03/09/2024
Last modified:
13/03/2025

Description

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:* 6.6.1\+240806 (including)