CVE-2025-41370 PUBLISHED

SQL injection vulnerability in Gandia Integra Total

Assigner: INCIBE
Reserved: 16.04.2025 Published: 01.08.2025 Updated: 01.08.2025

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb/html/view/acceso.php.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor TESI
Product Gandia Integra Total
Versions Default: unaffected
  • affected from 2.1.2217.3 to 4.4.2236.1 (excl.)

Solutions

The vulnerability has been fixed by the TESI team in version 4.4.2431.5.

Credits

  • David Utón Amaya (m3n0sd0n4ld) finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE