SQL Injection Vulnerability in Toools Isquad Product
CVE-2026-81677

8.8HIGH

Key Information:

Vendor

Toools

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81677?

The Toools Isquad product contains a SQL injection vulnerability in the '/ws/apiprensa/getVideo' endpoint, linked to inadequate validation of the GET parameter 'id_ambito'. This flaw allows an attacker to manipulate SQL queries, potentially leading to severe implications such as syntax errors and unintentional data exposure through database error messages. Proper input validation and the use of prepared statements are essential to mitigate this vulnerability and safeguard user data.

Affected Version(s)

iSquad 0 < 22/07/2026

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DylanCV
.