SQL Injection Vulnerability in Toools Isquad Affecting Visit Tracking
CVE-2026-81673
9.3CRITICAL
What is CVE-2026-81673?
The Toools Isquad application features an endpoint, '/ws/apitribuna/setVisita', that is exposed to SQL injection vulnerabilities through improperly validated parameters, specifically 'id_video' and 'id_ambito'. This lack of input sanitization allows malicious actors to manipulate SQL queries. As a result, attackers can introduce harmful SQL syntax, leading to erroneous database operations and potential disruption of visit tracking functionality. Such vulnerabilities threaten not only data integrity but also the reliability of analytics and associated records within the application.
Affected Version(s)
iSquad 0 < 22/07/2026
