Security Advisory

CVE-2025-41375

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-01 12:29:48
Last updated 2025-09-11 08:51:03
Assigner INCIBE
State PUBLISHED

Description

SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via token parameter in /index.php endpoint.