Vulnerability Description
SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Limesurvey | Limesurvey | >= 2.65.1, < 3.0.0 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-limeThird Party Advisory
FAQ
What is CVE-2025-41375?
CVE-2025-41375 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.
How severe is CVE-2025-41375?
CVE-2025-41375 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-41375?
Check the references section above for vendor advisories and patch information. Affected products include: Limesurvey Limesurvey.