6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Description
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.
Basic Information
ID
CVE-2025-41075
Source
INCIBE
Published
Nov 20, 2025 at 12:49
Modified
Nov 20, 2025 at 18:32
Affected Product
Vendor
LimeSurvey
Product
LimeSurvey
Version
6.13.0
Affected Versions
LimeSurvey LimeSurvey 6.13.0