Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23353 | CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%20POC'. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Sep 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| References |
|
Thu, 11 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php. | CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%20POC'. |
| Title | SQL injection vulnerability in Gandia Integra Total | CRLF Injection in Limesurvey |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 01 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php. | |
| Title | SQL injection vulnerability in Gandia Integra Total | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-11T08:56:57.154Z
Reserved: 2025-04-16T09:57:07.297Z
Link: CVE-2025-41376
Updated: 2025-08-01T13:18:15.937Z
Status : Awaiting Analysis
Published: 2025-08-01T13:15:27.450
Modified: 2025-09-11T09:15:33.717
Link: CVE-2025-41376
No data.
OpenCVE Enrichment
No data.
EUVD