VYPR
Unrated severityNVD Advisory· Published Sep 3, 2024· Updated Mar 13, 2025

CVE-2024-42903

CVE-2024-42903

Description

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.