A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tesigandia
Tesigandia gandia Integra Total |
|
CPEs | cpe:2.3:a:tesigandia:gandia_integra_total:*:*:*:*:*:*:*:* | |
Vendors & Products |
Tesigandia
Tesigandia gandia Integra Total |
|
Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/hislistadoacciones.php. | |
Title | SQL injection vulnerability in Gandia Integra Total | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-08-01T12:29:35.137Z
Updated: 2025-08-01T13:23:15.693Z
Reserved: 2025-04-16T09:57:06.081Z
Link: CVE-2025-41374

Updated: 2025-08-01T13:23:07.050Z

Status : Analyzed
Published: 2025-08-01T13:15:27.063
Modified: 2025-10-08T18:41:31.317
Link: CVE-2025-41374

No data.