216.73.217.22

CVE-2026-50635

· Published 09/06/2026 18:17 · Modified 09/06/2026 19:36

Labels: CVE-2026-50635 2026-06-09CVE-2026-50635CWE-640[email protected]

Essential information

Published
09/06/2026 18:17
Modified
09/06/2026 19:36
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
limeSurvey / limeSurvey cpe:2.3:a:limeSurvey:limeSurvey:*:*:*:*:*:*:limeSurvey:*:*

References