Medium severity6.5NVD Advisory· Published Sep 3, 2024· Updated Jun 17, 2026
CVE-2024-42903
CVE-2024-42903
Description
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*range: <=6.6.1\+240806
- (no CPE)
- (no CPE)range: <=v.6.6.1+240806
Patches
Vulnerability mechanics
References
3- github.com/LimeSurvey/LimeSurvey/compare/6.6.0+240729...6.6.1+240806nvdPatch
- github.com/sysentr0py/CVEs/tree/main/CVE-2024-42903nvdThird Party Advisory
- github.com/LimeSurvey/LimeSurvey/pull/3920nvdIssue Tracking
News mentions
0No linked articles in our index yet.