Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Sep 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 11 Sep 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultaincimails.php. | SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint. |
Title | SQL injection vulnerability in Gandia Integra Total | SQL Injection in Limesurvey |
References |
| |
Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 01 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultaincimails.php. | |
Title | SQL injection vulnerability in Gandia Integra Total | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-11T08:51:03.073Z
Reserved: 2025-04-16T09:57:07.297Z
Link: CVE-2025-41375

Updated: 2025-08-01T13:21:22.642Z

Status : Awaiting Analysis
Published: 2025-08-01T13:15:27.257
Modified: 2025-09-11T09:15:31.953
Link: CVE-2025-41375

No data.

No data.