CVE 8.7 HIGH

SQL injection vulnerability in Gandia Integra Total_CVE-2025-41376

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php.

Basic Information

ID CVE-2025-41376
Source INCIBE
Published Aug 1, 2025 at 12:29
Modified Aug 1, 2025 at 13:18

Affected Product

Vendor TESI
Product Gandia Integra Total
Version 2.1.2217.3
Affected Versions TESI Gandia Integra Total 2.1.2217.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.