CVE-2025-41373
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.
- Affected products
- Gandia Integra Total
- Tesigandia Gandia Integra Total
- ≤ 4.4.2236.1
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.1% (62th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2025-08-01
Fix
The vulnerability has been fixed by the TESI team in version 4.4.2431.5.
CVE-2025-41373 at NVD
2 known exploits for CVE-2025-41373
Proof-of-concept code and exploit modules indexed by Sploitus