SQL Injection Vulnerability in Video Management Tool by Vendor Name
CVE-2026-81672
9.3CRITICAL
What is CVE-2026-81672?
An SQL injection vulnerability exists in the '/ws/apiprensa/getVideoSubcanal' endpoint of the Video Management Tool due to improper handling of the 'id_video' parameter. The application fails to sanitize input, allowing for execution errors when malicious data is provided. This vulnerability could potentially expose internal file paths and complete stack traces via the Slim framework's error handler, combining the threats of SQL injection and information disclosure.
Affected Version(s)
iSquad 0 < 22/07/2026
