Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| CPEs | cpe:2.3:a:limesurvey:limesurvey:6.13.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| Metrics |
cvssV3_1
|
Thu, 20 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability. | |
| Title | Multiple vulnerabilities in Limesurvey | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-11-20T12:47:05.559Z
Updated: 2025-11-20T18:32:02.751Z
Reserved: 2025-04-16T09:09:34.459Z
Link: CVE-2025-41074
Updated: 2025-11-20T18:31:57.905Z
Status : Analyzed
Published: 2025-11-20T15:17:29.067
Modified: 2025-11-21T20:00:55.093
Link: CVE-2025-41074
No data.