PT-2026-82496 · Toools · Toools
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
TOOOLS (affected versions not specified)
Description
The endpoint '/ws/apiprensa/getVideoNextPrev' is susceptible to SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution. This occurs because unsanitized input provided via the
id ambito parameter is directly incorporated into a MariaDB query. This flaw allows attackers to interrupt query execution, triggering detailed database error messages that expose the internal structure of the queries.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the parameter
id ambito in the '/ws/apiprensa/getVideoNextPrev' endpoint until the issue is resolved.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Toools