A Host header injection vulnerability in the password...
Moderate severity
Unreviewed
Published
Sep 3, 2024
to the GitHub Advisory Database
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Sep 3, 2024
Published to the GitHub Advisory Database
Sep 3, 2024
Last updated
Sep 12, 2024
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
References