PT-2025-31632 · Gandia · Gandia Integra Total Tesi

Published

2025-08-01

·

Updated

2025-10-08

·

CVE-2025-41370

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gandia Integra Total TESI versions 2.1.2217.3 through 4.4.2236.1
Description A SQL injection vulnerability exists in Gandia Integra Total TESI. The vulnerability allows an authenticated attacker to retrieve, create, update, and delete databases. The vulnerability is located in the idestudio parameter within the /encuestas/integraweb/html/view/acceso.php API endpoint.
Recommendations Versions 2.1.2217.3 through 4.4.2236.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-41370

Affected Products

Gandia Integra Total Tesi