CVE-2026-1478
Out-of-band SQL injection in Quatuor Performance Evaluation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_evalua.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.
| CWE | CWE-89 |
| Vendor | quatuor |
| Product | evaluación de desempeño (edd) |
| Published | Jan 27, 2026 |
| Last Updated | Mar 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for quatuor evaluación de desempeño (edd)
Be the first to know when new unknown vulnerabilities affecting quatuor evaluación de desempeño (edd) are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Quatuor / Evaluación de Desempeño (EDD)
0 < 11/12/2025
References
Credits
Óscar Atienza Vendrell