SQL Injection Vulnerability in Video Management Tool by Vendor Name
CVE-2026-81672

9.3CRITICAL

Key Information:

Vendor

Toools

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81672?

An SQL injection vulnerability exists in the '/ws/apiprensa/getVideoSubcanal' endpoint of the Video Management Tool due to improper handling of the 'id_video' parameter. The application fails to sanitize input, allowing for execution errors when malicious data is provided. This vulnerability could potentially expose internal file paths and complete stack traces via the Slim framework's error handler, combining the threats of SQL injection and information disclosure.

Affected Version(s)

iSquad 0 < 22/07/2026

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DylanCV
.