PT-2026-82496 · Toools · Toools

·

CVE-2026-81674

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TOOOLS (affected versions not specified)
Description The endpoint '/ws/apiprensa/getVideoNextPrev' is susceptible to SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution. This occurs because unsanitized input provided via the id ambito parameter is directly incorporated into a MariaDB query. This flaw allows attackers to interrupt query execution, triggering detailed database error messages that expose the internal structure of the queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the parameter id ambito in the '/ws/apiprensa/getVideoNextPrev' endpoint until the issue is resolved.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81674

Affected Products

Toools