CVE-2025-41076 MEDIUM

CVE-2025-41076: Multiple vulnerabilities in Limesurvey

Vendor Limesurvey
Product LimeSurvey
Weakness CWE-209 · Error message info leak
Published November 20, 2025
Last update November 20, 2025

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker.

Key dates

02Disclosure timeline

November 20, 2025 CVE published
November 20, 2025 Record updated