A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of the backend system.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toools
Toools isquad |
|
| Vendors & Products |
Toools
Toools isquad |
Thu, 27 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of the backend system. | |
| Title | Multiple Vulnerabilities in TOOOLS' iSquad | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2026-08-27T12:08:54.658Z
Updated: 2026-08-27T15:38:39.538Z
Reserved: 2026-08-27T10:59:54.611Z
Link: CVE-2026-81676
Updated: 2026-08-27T15:38:35.955Z
Status : Deferred
Published: 2026-08-27T13:18:43.190
Modified: 2026-08-28T18:58:47.740
Link: CVE-2026-81676
No data.