PT-2026-82498 · Toools · Isquad

·

CVE-2026-81676

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TOOOLS iSquad (affected versions not specified)
Description An error-based SQL injection exists in the '/ws/apitribuna/ultimosVideos' endpoint. The limit videos parameter is concatenated directly into a MariaDB SQL query without proper sanitization or parameterization. A remote attacker can inject SQL syntax into this parameter to cause syntax errors, manipulate backend queries, and expose internal database error messages and stack traces, which reveals backend implementation details.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the limit videos parameter in the '/ws/apitribuna/ultimosVideos' endpoint until the issue is resolved.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81676

Affected Products

Isquad