SQL Injection Vulnerability in Toools Isquad Product
CVE-2026-81675

9.3CRITICAL

Key Information:

Vendor

Toools

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81675?

The Toools Isquad product is vulnerable to an SQL injection attack through the id_seccion parameter of the endpoint '/ws/apiprensa/getVideoUltimasSeccion'. An attacker can manipulate this parameter to alter the structure of the SQL query executed on the database, leading to potential data breaches and unauthorized access to sensitive information. This vulnerability poses significant risks due to the complexity of the SQL operations involved, which may allow attackers to execute broader queries and manipulate the logic for content retrieval, ultimately compromising data integrity and system functionality.

Affected Version(s)

iSquad 0 < 22/07/2026

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DylanCV
.