SQL Injection Vulnerability in Toools Isquad Product
CVE-2026-81675
9.3CRITICAL
What is CVE-2026-81675?
The Toools Isquad product is vulnerable to an SQL injection attack through the id_seccion parameter of the endpoint '/ws/apiprensa/getVideoUltimasSeccion'. An attacker can manipulate this parameter to alter the structure of the SQL query executed on the database, leading to potential data breaches and unauthorized access to sensitive information. This vulnerability poses significant risks due to the complexity of the SQL operations involved, which may allow attackers to execute broader queries and manipulate the logic for content retrieval, ultimately compromising data integrity and system functionality.
Affected Version(s)
iSquad 0 < 22/07/2026
