← Volver al buscador de CVEs

CVE-2026-50635

LimeSurvey

Descripción

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target-s username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host-s newPassword endpoint to set a new password and take over the account.

CVSS 8.8EPSS 0.372%Riesgo 0.91
Ver fuente
Publicación
2026-06-09 18:17:10
Versiones afectadas
unknown
Tipo
Core software
Última modificación
2026-07-23 08:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H