← back
CVE-2025-41373highCWE-89

SQL injection vulnerability in Gandia Integra Total

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 8.7epss 1.1%
from disclosure to weapon0 days
Published on NVDAug 1
1st PoCAug 1
exploitation probability
1.1%top 37% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.