Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| CPEs | cpe:2.3:a:limesurvey:limesurvey:6.13.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| Metrics |
cvssV3_1
|
Thu, 20 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability. | |
| Title | Multiple vulnerabilities in Limesurvey | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-11-20T12:49:29.997Z
Updated: 2025-11-20T18:32:58.485Z
Reserved: 2025-04-16T09:09:35.596Z
Link: CVE-2025-41075
Updated: 2025-11-20T18:32:39.477Z
Status : Analyzed
Published: 2025-11-20T15:17:29.263
Modified: 2025-11-21T19:59:05.430
Link: CVE-2025-41075
No data.