Description
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2433 Vulnerability (CVE-2013-2433)
SharePoint CVE-2022-21840 Vulnerability (CVE-2022-21840)
WordPress Plugin Share Drafts Publicly Information Disclosure (1.1.4)
WordPress Plugin 301 Redirects-Easy Redirect Manager Security Bypass (2.40)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3370)