LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host header in the getTemplateData() function to reach internal network services, cloud metadata endpoints, and extract sensitive credentials such as IAM tokens from instance metadata services.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jul 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:* |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
Mon, 20 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit the unsanitized use of the HTTP Host header in the getTemplateData() function to reach internal network services, cloud metadata endpoints, and extract sensitive credentials such as IAM tokens from instance metadata services. | |
| Title | LimeSurvey SSRF via REST API Survey Template Host Header | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-20T18:14:01.625Z
Updated: 2026-07-28T01:05:28.861Z
Reserved: 2026-07-15T15:45:44.602Z
Link: CVE-2026-63107
Updated: 2026-07-23T18:51:33.624Z
Status : Deferred
Published: 2026-07-20T19:17:28.913
Modified: 2026-07-23T20:17:20.100
Link: CVE-2026-63107
No data.