In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Limesurvey
Limesurvey limesurvey |
|
| CPEs | cpe:2.3:a:limesurvey:limesurvey:6.13.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Limesurvey
Limesurvey limesurvey |
|
| Metrics |
cvssV3_1
|
Thu, 20 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker. | |
| Title | Multiple vulnerabilities in Limesurvey | |
| Weaknesses | CWE-209 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-11-20T12:52:25.797Z
Updated: 2025-11-20T20:30:01.872Z
Reserved: 2025-04-16T09:09:35.597Z
Link: CVE-2025-41076
Updated: 2025-11-20T20:22:29.403Z
Status : Analyzed
Published: 2025-11-20T15:17:29.427
Modified: 2025-11-21T19:54:57.150
Link: CVE-2025-41076
No data.