Vulnerability Description
CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.php/survey/index/sid/<SID>/token/fwyfw%0d%0aCookie:%20POC'.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Limesurvey | Limesurvey | >= 2.65.1, < 3.0.0 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-limeThird Party Advisory
FAQ
What is CVE-2025-41376?
CVE-2025-41376 is a vulnerability with a CVSS score of 5.3 (MEDIUM). CRLF Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via '/index.ph...
How severe is CVE-2025-41376?
CVE-2025-41376 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-41376?
Check the references section above for vendor advisories and patch information. Affected products include: Limesurvey Limesurvey.