CVE-2025-41074: Multiple vulnerabilities in Limesurvey
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41074?
CVE-2025-41074 is classified as a Denial of Service (DoS) vulnerability that can exhaust server or client resources.
How do I fix CVE-2025-41074?
To fix CVE-2025-41074, update LimeSurvey to a version that addresses this vulnerability as soon as possible.
What systems are affected by CVE-2025-41074?
CVE-2025-41074 specifically affects LimeSurvey version 6.13.0 when accessing the /optout endpoint.
What can be exploited in CVE-2025-41074?
CVE-2025-41074 can be exploited to perform infinite HTTP redirects, leading to a Denial of Service attack.
What should I monitor for regarding CVE-2025-41074?
Monitor your server for unusual traffic patterns that may indicate exploitation attempts of CVE-2025-41074.