CVE Details
Basic Information
| Title | SQL injection vulnerability in Gandia Integra Total |
|---|---|
| Type | cve |
| Published | 2025-08-01T12:29:59.023Z |
| Modified | 2025-08-01T13:18:25.260Z |
Product Information
| Vendor | TESI |
|---|---|
| Product | Gandia Integra Total |
| Version | 2.1.2217.3 |
CVSS Information
| Base Score | 8.7 (HIGH) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Affected Products
- TESI Gandia Integra Total 2.1.2217.3
Additional Information
| CWE List | CWE-89 |
|---|---|
| Source | INCIBE |
Description
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the ‘idestudio’ parameter in /encuestas/integraweb[_v4]/integra/html/view/consultacuotasred.php.