CVE-2025-41376: CRLF Injection in Limesurvey
Published Aug 1, 2025
·Updated
CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%20POC'.
Affected Software
2 affected components
Limesurvey LimeSurvey>=2.65.1+170522
Limesurvey LimeSurvey>=2.65.1<3.0.0
Remediation
Information
The vulnerability has been fixed by the TESI team in version 4.4.2431.5.
Event History
Aug 1, 2025
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-41376?
CVE-2025-41376 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2025-41376?
To fix CVE-2025-41376, update your Gandia Integra Total software to version 4.4.2236.2 or later.
3
Which versions of Gandia Integra Total are affected by CVE-2025-41376?
The affected versions of Gandia Integra Total range from 2.1.2217.3 to 4.4.2236.1.
4
What type of attack can exploit CVE-2025-41376?
CVE-2025-41376 can be exploited by authenticated attackers to perform SQL injection attacks.
5
What impact does CVE-2025-41376 have on affected systems?
CVE-2025-41376 allows an attacker to access, modify, and delete database information.