Information Exposure Affecting limesurvey/limesurvey package, versions <6.15.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Information Exposure vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-LIMESURVEYLIMESURVEY-14075609
  • published21 Nov 2025
  • disclosed20 Nov 2025
  • creditJulen Garrido Estevez

Introduced: 20 Nov 2025

NewCVE-2025-41076  (opens in a new tab)
CWE-209  (opens in a new tab)

How to fix?

Upgrade limesurvey/limesurvey to version 6.15.0 or higher.

Overview

limesurvey/limesurvey is a FOSS online survey tool on the web.

Affected versions of this package are vulnerable to Information Exposure via the handling of malformed session cookies. An attacker can obtain sensitive internal backend information, such as framework details, database engine, table names, primary keys, and fragments of session data, by sending a specially crafted session cookie that triggers a server error 500.

References

CVSS Base Scores

version 4.0
version 3.1