PT-2026-61687 · Unknown · Limesurvey
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LimeSurvey versions 6.x through 6.17.10
LimeSurvey versions 7.x through 7.0.4
Description
Authenticated users can trigger a server-side request forgery (SSRF) by providing a manipulated Host header. This occurs due to the unsanitized use of the HTTP Host header within the
getTemplateData() function in the REST API survey template endpoint. This flaw allows attackers to force the server to issue arbitrary HTTP requests, potentially enabling access to internal network services and cloud metadata endpoints to extract sensitive credentials, such as IAM tokens from instance metadata services.Recommendations
Restrict network access and monitor for abuse.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Limesurvey