🔐 CVE Alert

CVE-2026-1478

UNKNOWN 0.0

Out-of-band SQL injection in Quatuor Performance Evaluation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_evalua.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.

CWE CWE-89
Vendor quatuor
Product evaluación de desempeño (edd)
Published Jan 27, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for quatuor evaluación de desempeño (edd)

Be the first to know when new unknown vulnerabilities affecting quatuor evaluación de desempeño (edd) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Quatuor / Evaluación de Desempeño (EDD)
0 < 11/12/2025

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/out-band-sql-injection-quatuor-performance-evaluation

Credits

Óscar Atienza Vendrell