Description
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4408)
WordPress Plugin Quick Featured Images Cross-Site Scripting (12.3.5)
WordPress Plugin Translate Multilingual sites-TranslatePress Cross-Site Scripting (2.0.8)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)