The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt the query structure and cause database errors, exposing the internal logic of the queries. The complexity of the query increases the potential impact, as it could allow for broader manipulation of the content retrieval logic.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toools
Toools isquad |
|
| Vendors & Products |
Toools
Toools isquad |
Thu, 27 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt the query structure and cause database errors, exposing the internal logic of the queries. The complexity of the query increases the potential impact, as it could allow for broader manipulation of the content retrieval logic. | |
| Title | Multiple Vulnerabilities in TOOOLS' iSquad | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2026-08-27T12:07:48.303Z
Updated: 2026-08-27T15:39:59.092Z
Reserved: 2026-08-27T10:59:53.398Z
Link: CVE-2026-81675
Updated: 2026-08-27T15:39:56.309Z
Status : Deferred
Published: 2026-08-27T13:18:43.047
Modified: 2026-08-28T18:58:47.740
Link: CVE-2026-81675
No data.