Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23356 | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php. |
Solution
The vulnerability has been fixed by the TESI team in version 4.4.2431.5.
Workaround
No workaround given by the vendor.
Wed, 08 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tesigandia
Tesigandia gandia Integra Total |
|
| CPEs | cpe:2.3:a:tesigandia:gandia_integra_total:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tesigandia
Tesigandia gandia Integra Total |
|
| Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php. | |
| Title | SQL injection vulnerability in Gandia Integra Total | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-08-01T13:25:28.243Z
Reserved: 2025-04-16T09:57:06.080Z
Link: CVE-2025-41373
Updated: 2025-08-01T13:25:20.521Z
Status : Analyzed
Published: 2025-08-01T13:15:26.873
Modified: 2025-10-08T18:41:23.173
Link: CVE-2025-41373
No data.
OpenCVE Enrichment
No data.
EUVD