CVE-2024-42903: Medium severity limesurvey vulnerability
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42903?
CVE-2024-42903 is classified as a medium severity vulnerability due to its potential to direct users to malicious domains.
How do I fix CVE-2024-42903?
To fix CVE-2024-42903, update LimeSurvey to version 6.6.1+240807 or later.
What types of attacks are possible with CVE-2024-42903?
CVE-2024-42903 allows attackers to execute host header injection attacks leading to phishing attempts through crafted password reset links.
Which versions of LimeSurvey are affected by CVE-2024-42903?
LimeSurvey versions prior to 6.6.1+240806 are vulnerable to CVE-2024-42903.
Can CVE-2024-42903 affect my user data?
Yes, CVE-2024-42903 can potentially compromise user data by tricking users into visiting malicious domains via manipulated password reset links.