Aller au contenu

Fiche vulnérabilité

CVE-2025-41075 : faille élevée limesurvey limesurvey (CVSS 7.5)

Description

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
20 nov. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • limesurvey limesurvey

Références

Rechercher une autre vulnérabilité dans la base CVE