Back

CRITICAL

SQL injection vulnerability in Gandia Integra Total

Published Aug 1, 2025

Description

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb_v4/integra/html/view/acceso.php

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by the TESI team in version 4.4.2431.5.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Aug 1, 2025
Updated Aug 1, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Aug 1, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a