PT-2025-31632 · Gandia · Gandia Integra Total Tesi
Published
2025-08-01
·
Updated
2025-10-08
·
CVE-2025-41370
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Gandia Integra Total TESI versions 2.1.2217.3 through 4.4.2236.1
Description
A SQL injection vulnerability exists in Gandia Integra Total TESI. The vulnerability allows an authenticated attacker to retrieve, create, update, and delete databases. The vulnerability is located in the
idestudio parameter within the /encuestas/integraweb/html/view/acceso.php API endpoint.Recommendations
Versions 2.1.2217.3 through 4.4.2236.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gandia Integra Total Tesi