Description
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.
Remediation
References
Related Vulnerabilities
WordPress Plugin Backend Localization Multiple Cross-Site Scripting Vulnerabilities (1.6.1)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Request Forgery (5.1.0)
Oracle Database Server CVE-2014-6467 Vulnerability (CVE-2014-6467)
WordPress Plugin Enable Media Replace Unspecified Vulnerability (2.9.5)