PT-2026-82497 · Toools · Isquad
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TOOOLS iSquad (affected versions not specified)
Description
The endpoint '/ws/apiprensa/getVideoUltimasSeccion' is susceptible to SQL injection via the
id seccion parameter. This parameter is directly embedded into a complex SQL query involving grouping and sorting operations. An attacker can inject SQL syntax to disrupt the query structure, trigger database errors, and expose internal query logic, potentially allowing for broader manipulation of how content is retrieved.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the parameter
id seccion in the '/ws/apiprensa/getVideoUltimasSeccion' endpoint until the issue is resolved.SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Isquad