Back to search
CVE-2025-41073
Published: Oct 23, 2025
Modified: Oct 23, 2025
PUBLISHED
Description
Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file containing files from the server, including those located in parent directories (e.g., ..\..\..), by exploiting the “direstudio” parameter in “/encuestas/integraweb[_v4]/integra/html/view/comprimir.php”.
| Vendor | Product | Versions |
|---|---|---|
TESI | Gandia Integra Total | affected 0 - < 4.4.2246.2 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now