CVE-2024-42903: Limesurvey

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.

Affected products

  • Limesurvey Limesurvey: up to and including 6.6.1\+240806

Published 2024-09-03. Last modified 2026-06-17.