External User Affects LimeSurvey through Malformed Session Cookie
CVE-2025-41076
What is CVE-2025-41076?
In LimeSurvey version 6.13.0, a vulnerability exists that allows external users to trigger a 500 error in the survey system by sending a malformed session cookie. Instead of a generic error response, the system reveals internal backend information including details related to the Yii framework, MySQL/MariaDB database engine, and specific database table structures. This leakage of sensitive information can aid attackers in understanding the system's architecture and potentially exploiting other weaknesses.
Affected Version(s)
LimeSurvey 6.13.0
News Articles
CVE-2025-41076 Impact, Exploitability, and Mitigation Steps | Wiz
Understand the critical aspects of CVE-2025-41076 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
3 weeks ago
References
CVSS V4
Timeline
- 📰
First article discovered by wiz.io
Vulnerability published
Vulnerability Reserved
