Ad

CVE-2025-41074

HIGH CVSS 3.1: 7.5 EPSS 0.08%
Updated Nov 21, 2025
Limesurvey
Parameter Value
CVSS 7.5 (HIGH)
Type CWE-835
Vendor Limesurvey
Public PoC No

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation of Service (DoS attack), by exhausting server or client resources. The system is unable to break the redirect loop, which can cause service degradation or browser instability.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Limesurvey Limesurvey
cpe:2.3:a:limesurvey:limesurvey:6.13.0:*:*:*:*:*:*:*