CVE-2025-41076 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a gen…
Medium CVSS: 6.9

CVE-2025-41076

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker.
Vendor
Limesurvey
Product
Limesurvey
CWE
CWE-209
Yayın Tarihi
2025-11-20 15:17:29
Güncelleme
2025-11-21 19:54:57
Source Identifier
cve-coordination@incibe.es
KEV Date Added
-

Kategoriler

Referanslar