Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c37-5j7w-8mh8

Опубликовано: 09 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it.

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.

Пакеты

Наименование

limesurvey/limesurvey

composer
Затронутые версииВерсия исправления

<= 7.0.0-beta1

Отсутствует

EPSS

Процентиль: 29%
0.00372
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 8.8
nvd
2 месяца назад

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.

CVSS3: 8.8
debian
2 месяца назад

LimeSurvey constructs account password-reset links from the client-sup ...

EPSS

Процентиль: 29%
0.00372
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-640