In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of displaying a generic error message, the system exposes internal backend information, including the use of the Yii framework, the MySQL/MariaDB database engine, the table name 'lime_sessions', primary keys, and fragments of the content that caused the conflict. This information can simplify the collection of data about the internal architecture of the application by an attacker.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/41xxx/CVE-2025-41076.json",
"cna_assigner": "INCIBE",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "6.13.0"
},
{
"last_affected": "6.13.0"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-209"
]
}