CVE-2026-81677
Multiple Vulnerabilities in TOOOLS' iSquad
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of database error messages via PDOException. This confirms that user input is being incorporated directly into SQL statements without proper sanitization or the use of prepared statements.
| CWE | CWE-89 |
| Vendor | toools |
| Product | isquad |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for toools isquad
Be the first to know when new unknown vulnerabilities affecting toools isquad are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TOOOLS / iSquad
0 < 22/07/2026
References
Credits
DylanCV