External User Affects LimeSurvey through Malformed Session Cookie
CVE-2025-41076

6.9MEDIUM

Key Information:

Vendor

Limesurvey

Vendor
CVE Published:
20 November 2025

What is CVE-2025-41076?

In LimeSurvey version 6.13.0, a vulnerability exists that allows external users to trigger a 500 error in the survey system by sending a malformed session cookie. Instead of a generic error response, the system reveals internal backend information including details related to the Yii framework, MySQL/MariaDB database engine, and specific database table structures. This leakage of sensitive information can aid attackers in understanding the system's architecture and potentially exploiting other weaknesses.

Affected Version(s)

LimeSurvey 6.13.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julen Garrido Estevez
.
CVE-2025-41076 : External User Affects LimeSurvey through Malformed Session Cookie