CVE-2025-41372: Tesigandia Gandia Integra Total
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/informe_campo_entrevistas.php.
Affected products
- Tesigandia Gandia Integra Total: from 2.1.2217.3, up to and including 4.4.2236.1
Published 2025-08-01. Last modified 2026-06-17.