SQL Injection Vulnerability in Toools Isquad Product
CVE-2026-81677
8.8HIGH
What is CVE-2026-81677?
The Toools Isquad product contains a SQL injection vulnerability in the '/ws/apiprensa/getVideo' endpoint, linked to inadequate validation of the GET parameter 'id_ambito'. This flaw allows an attacker to manipulate SQL queries, potentially leading to severe implications such as syntax errors and unintentional data exposure through database error messages. Proper input validation and the use of prepared statements are essential to mitigate this vulnerability and safeguard user data.
Affected Version(s)
iSquad 0 < 22/07/2026
