Home

Description

Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file containing files from the server, including those located in parent directories (e.g., ..\..\..), by exploiting the “direstudio” parameter in “/encuestas/integraweb[_v4]/integra/html/view/comprimir.php”.

PUBLISHED Reserved 2025-04-16 | Published 2025-10-23 | Updated 2025-10-23 | Assigner INCIBE




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

Any version before 4.4.2246.2
affected

Credits

David Utón Amaya (m3n0sd0n4ld) finder

References

www.incibe.es/...so/path-traversal-gandia-integra-total-tesi

cve.org (CVE-2025-41073)

nvd.nist.gov (CVE-2025-41073)

Download JSON