Impact
An endpoint (/ws/apitribuna/setVisita) in the iSquad application accepted unvalidated input in the id_video and id_ambito parameters, enabling an attacker to inject raw SQL syntax. The injection could cause database errors and alter visit-tracking data, thereby compromising the integrity of analytics and allowing unauthorized data manipulation.
Affected Systems
Targeted components belong to the TOOOLS iSquad service hosted and operated by Toools S.L. No specific product version numbers are disclosed, but the issue was present in all production deployments of iSquad accessed through the vulnerable endpoint. The vendor has already applied a fix across all instances, eliminating the exposure.
Risk and Exploitability
Prior to remediation, the CVSS score of 9.3 categorized the flaw as critical, and the vulnerability was not listed in the CISA KEV catalog. Although EPSS data is not available, the severity level implied a high likelihood of exploitation by remote attackers with network access to the endpoint. The vendor’s retest demonstrates that the issue is no longer exploitable and no internal error messages are returned, effectively neutralizing the attack surface.
OpenCVE Enrichment