Vulnerability Details CVE-2025-41375
SQL Injection vulnerability in Limesurvey v2.65.1+170522. This vulnerability allows an attacker to retrieve, create, update and delete database via 'token' parameter in '/index.php' endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-41375
-
cpe:2.3:a:limesurvey:limesurvey:2.65.1
-
cpe:2.3:a:limesurvey:limesurvey:2.65.2
-
cpe:2.3:a:limesurvey:limesurvey:2.65.3
-
cpe:2.3:a:limesurvey:limesurvey:2.65.4
-
cpe:2.3:a:limesurvey:limesurvey:2.65.5
-
cpe:2.3:a:limesurvey:limesurvey:2.65.6
-
cpe:2.3:a:limesurvey:limesurvey:2.66.6
-
cpe:2.3:a:limesurvey:limesurvey:2.67.0
-
cpe:2.3:a:limesurvey:limesurvey:2.67.1
-
cpe:2.3:a:limesurvey:limesurvey:2.67.2
-
cpe:2.3:a:limesurvey:limesurvey:2.67.3
-
cpe:2.3:a:limesurvey:limesurvey:2.70.0
-
cpe:2.3:a:limesurvey:limesurvey:2.71.0
-
cpe:2.3:a:limesurvey:limesurvey:2.71.1
-
cpe:2.3:a:limesurvey:limesurvey:2.72.0
-
cpe:2.3:a:limesurvey:limesurvey:2.72.1
-
cpe:2.3:a:limesurvey:limesurvey:2.72.2
-
cpe:2.3:a:limesurvey:limesurvey:2.72.3
-
cpe:2.3:a:limesurvey:limesurvey:2.72.4
-
cpe:2.3:a:limesurvey:limesurvey:2.72.5
-
cpe:2.3:a:limesurvey:limesurvey:2.72.6
-
cpe:2.3:a:limesurvey:limesurvey:2.73.0
-
cpe:2.3:a:limesurvey:limesurvey:2.73.1