In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker.
History

Fri, 21 Nov 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Limesurvey
Limesurvey limesurvey
CPEs cpe:2.3:a:limesurvey:limesurvey:6.13.0:*:*:*:*:*:*:*
Vendors & Products Limesurvey
Limesurvey limesurvey
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 20 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
Description In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker.
Title Multiple vulnerabilities in Limesurvey
Weaknesses CWE-209
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-11-20T12:52:25.797Z

Updated: 2025-11-20T20:30:01.872Z

Reserved: 2025-04-16T09:09:35.597Z

Link: CVE-2025-41076

cve-icon Vulnrichment

Updated: 2025-11-20T20:22:29.403Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-20T15:17:29.427

Modified: 2025-11-21T19:54:57.150

Link: CVE-2025-41076

cve-icon Redhat

No data.