CVE-2025-41375: SQL Injection in Limesurvey
Published Aug 1, 2025
·Updated
SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.
Affected Software
2 affected components
Limesurvey LimeSurvey>=2.65.1+170522
Limesurvey LimeSurvey>=2.65.1<3.0.0
Remediation
Information
The vulnerability has been fixed by the TESI team in version 4.4.2431.5.
Event History
Aug 1, 2025
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41375?
CVE-2025-41375 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2025-41375?
To mitigate CVE-2025-41375, update Gandia Integra Total to a version later than 4.4.2236.1 or implement input validation on the 'idestudio' parameter.
3
Who is affected by CVE-2025-41375?
CVE-2025-41375 affects users of Gandia Integra Total versions from 2.1.2217.3 to 4.4.2236.1.
4
What can an attacker do with CVE-2025-41375?
An authenticated attacker exploiting CVE-2025-41375 can retrieve, create, update, and delete databases using the 'idestudio' parameter.
5
Is CVE-2025-41375 remotely exploitable?
CVE-2025-41375 requires authentication, but once authenticated, it can be exploited remotely.