8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php.
Basic Information
ID
CVE-2025-41376
Source
INCIBE
Published
Aug 1, 2025 at 12:29
Modified
Aug 1, 2025 at 13:18
Affected Product
Vendor
TESI
Product
Gandia Integra Total
Version
2.1.2217.3
Affected Versions
TESI Gandia Integra Total 2.1.2217.3