SQL Injection Vulnerability in MariaDB Affected by ISquad Tools
CVE-2026-81676
8.8HIGH
What is CVE-2026-81676?
A vulnerability exists in ISquad Tools related to the '/ws/apitribuna/ultimosVideos' endpoint, where the limit_videos parameter is vulnerable to SQL injection. Lack of proper sanitization allows attackers to inject SQL syntax, triggering error-based SQL injection and revealing internal database error messages and stack traces. This can lead to unauthorized manipulation of backend queries and expose sensitive implementation details of the system.
Affected Version(s)
iSquad 0 < 22/07/2026
