Impact
An endpoint named /ws/apiprensa/getVideoUltimasSeccion is vulnerable to SQL injection through the id_seccion parameter. The parameter is embedded directly into a complex query that includes grouping and sorting operations. Injection of SQL syntax can break the query structure and generate database errors, revealing internal query logic. This flaw carries a high risk of data exposure or denial‑of‑service. The flaw is classified under CWE‑89.
Affected Systems
The vulnerable component is the iSquad service operated by Toools S.L. No specific product version is listed; all production instances have been updated by the vendor.
Risk and Exploitability
The CVSS score is 9.3, indicating a severe threat, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The reported attack vectors have been reproduced and confirmed to be no longer exploitable after vendor remediation. The likely attack vector is an HTTP request to the aforementioned endpoint with a malicious id_seccion payload. Current mitigation removes the risk of exploitation.
OpenCVE Enrichment