PKSA-bgzx-wwbd-v2zr Security Advisory
-
[HIGH] LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it.
PKSA-bgzx-wwbd-v2zr CVE-2026-50635 GHSA-5c37-5j7w-8mh8
Affected package: limesurvey/limesurvey
Affected version: <=7.0.0-beta1
Reported by:
GitHub