CVE-2025-41075: Multiple vulnerabilities in Limesurvey
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41075?
CVE-2025-41075 has a high severity level due to its potential to cause Denial of Service attacks.
How does CVE-2025-41075 affect LimeSurvey?
CVE-2025-41075 causes infinite HTTP redirects in LimeSurvey, leading to resource exhaustion.
What are the potential impacts of CVE-2025-41075?
The impact of CVE-2025-41075 can result in a Denial of Service, affecting both server and client resources.
How can I fix CVE-2025-41075?
To fix CVE-2025-41075, update LimeSurvey to the latest version that addresses this vulnerability.
Is CVE-2025-41075 easy to exploit?
CVE-2025-41075 is relatively easy to exploit, as it requires simply accessing the affected endpoint.