Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Sep 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-89 | |
References |
|
Thu, 11 Sep 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php. | CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%20POC'. |
Title | SQL injection vulnerability in Gandia Integra Total | CRLF Injection in Limesurvey |
Weaknesses | CWE-93 | |
References |
| |
Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 01 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php. | |
Title | SQL injection vulnerability in Gandia Integra Total | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-11T08:56:57.154Z
Reserved: 2025-04-16T09:57:07.297Z
Link: CVE-2025-41376

Updated: 2025-08-01T13:18:15.937Z

Status : Awaiting Analysis
Published: 2025-08-01T13:15:27.450
Modified: 2025-09-11T09:15:33.717
Link: CVE-2025-41376

No data.

No data.