SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The vulnerability exposes internal file paths and complete stack traces through the Slim framework’s error handler, which increases the severity due to the combination of information disclosure and SQL injection.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toools
Toools isquad |
|
| Vendors & Products |
Toools
Toools isquad |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The vulnerability exposes internal file paths and complete stack traces through the Slim framework’s error handler, which increases the severity due to the combination of information disclosure and SQL injection. | |
| Title | Multiple Vulnerabilities in TOOOLS' iSquad | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2026-08-27T11:53:35.259Z
Updated: 2026-08-27T15:04:10.313Z
Reserved: 2026-08-27T10:59:50.036Z
Link: CVE-2026-81672
Updated: 2026-08-27T14:56:06.070Z
Status : Deferred
Published: 2026-08-27T13:18:42.610
Modified: 2026-08-28T18:58:47.740
Link: CVE-2026-81672
No data.