PT-2026-48152 · Unknown · Limesurvey
CVE-2026-50635
·
Published
2026-06-09
·
Updated
2026-06-15
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LimeSurvey (affected versions not specified)
Description
LimeSurvey constructs account password-reset links using the HTTP Host header provided by the client without proper validation. Because the
allowedHosts allowlist is undefined in the default configuration, the checkIsAllowedHost() function does not restrict the host. A remote, unauthenticated attacker can submit a forgotten-password request for a known account using a spoofed Host header. This causes the system to send an email containing a reset link with an attacker-controlled hostname but a genuine validation key. If the recipient or an automated security scanner follows the link, the valid reset token is disclosed to the attacker, who can then use it at the newPassword endpoint to change the password and take over the account.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Limesurvey