PT-2026-82495 · Toools · Isquad
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
TOOOLS iSquad (affected versions not specified)
Description
The '/ws/apitribuna/setVisita' endpoint is susceptible to SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution. This occurs because the application fails to validate or sanitize the
id video and id ambito parameters before incorporating them into SQL queries. A remote attacker can exploit this to disrupt query execution, trigger database errors, and manipulate visit tracking records, which may compromise the integrity of analytics and record accuracy.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
id video and id ambito parameters in the '/ws/apitribuna/setVisita' endpoint until the issue is resolved.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Isquad