CVE-2025-41375

Publication date

2025-08-01 12:29:48

Family

INCIBE

State

PUBLISHED

Description

SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via token parameter in /index.php endpoint.