PT-2025-43440 · Tesi · Gandia Integra Total Tesi

Published

2025-10-23

·

Updated

2025-10-30

·

CVE-2025-41073

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TESI Gandia Integra Total version 4.4.2236.1
Description An authenticated attacker can download a ZIP file containing files from the server, including those in parent directories. This is possible by exploiting the direstudio parameter in the '/encuestas/integraweb[ v4]/integra/html/view/comprimir.php' API endpoint. The issue allows access to files located outside the intended directory, such as using '......' to traverse the file system.
Recommendations Apply a fix for TESI Gandia Integra Total version 4.4.2236.1. As a temporary workaround, restrict access to the '/encuestas/integraweb[ v4]/integra/html/view/comprimir.php' endpoint. Sanitize the direstudio parameter to prevent directory traversal attempts.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-41073

Affected Products

Gandia Integra Total Tesi