Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
The vulnerabilities have been fixed by the Limesurvey team in the version 6.15.0.
Workaround
No workaround given by the vendor.
Fri, 21 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| CPEs | cpe:2.3:a:limesurvey:limesurvey:6.13.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| Metrics |
cvssV3_1
|
Thu, 20 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability. | |
| Title | Multiple vulnerabilities in Limesurvey | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-11-20T18:32:02.751Z
Reserved: 2025-04-16T09:09:34.459Z
Link: CVE-2025-41074
Updated: 2025-11-20T18:31:57.905Z
Status : Analyzed
Published: 2025-11-20T15:17:29.067
Modified: 2025-11-21T20:00:55.093
Link: CVE-2025-41074
No data.
OpenCVE Enrichment
No data.