PT-2026-82495 · Toools · Isquad

·

CVE-2026-81673

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TOOOLS iSquad (affected versions not specified)
Description The '/ws/apitribuna/setVisita' endpoint is susceptible to SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution. This occurs because the application fails to validate or sanitize the id video and id ambito parameters before incorporating them into SQL queries. A remote attacker can exploit this to disrupt query execution, trigger database errors, and manipulate visit tracking records, which may compromise the integrity of analytics and record accuracy.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the id video and id ambito parameters in the '/ws/apitribuna/setVisita' endpoint until the issue is resolved.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81673

Affected Products

Isquad