SQL Injection Vulnerability in TOOLS isQUAD by INGENIA
CVE-2026-81674

9.3CRITICAL

Key Information:

Vendor

Toools

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81674?

The TOOLS isQUAD application has a security weakness in the '/ws/apiprensa/getVideoNextPrev' endpoint, which is susceptible to SQL injection through the 'id_ambito' parameter. This vulnerability arises from the failure to sanitize user input before it is embedded into a MariaDB query. As a result, attackers can manipulate the SQL syntax, leading to potentially disruptive query executions. The exposure of detailed database error messages may not only reveal sensitive information regarding the database structure but also enable attackers to craft more sophisticated exploitation attempts.

Affected Version(s)

iSquad 0 < 22/07/2026

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DylanCV
.