SQL Injection Vulnerability in TOOLS isQUAD by INGENIA
CVE-2026-81674
9.3CRITICAL
What is CVE-2026-81674?
The TOOLS isQUAD application has a security weakness in the '/ws/apiprensa/getVideoNextPrev' endpoint, which is susceptible to SQL injection through the 'id_ambito' parameter. This vulnerability arises from the failure to sanitize user input before it is embedded into a MariaDB query. As a result, attackers can manipulate the SQL syntax, leading to potentially disruptive query executions. The exposure of detailed database error messages may not only reveal sensitive information regarding the database structure but also enable attackers to craft more sophisticated exploitation attempts.
Affected Version(s)
iSquad 0 < 22/07/2026
