Impact
A flaw in the /ws/apitribuna/ultimosVideos endpoint caused the limit_videos parameter to be concatenated directly into a MariaDB query, enabling a remote attacker to inject SQL payloads. The injection leads to error‑based exploitation that reveals internal database error messages and stack traces, thereby exposing implementation details. The vulnerability carries a CVSS score of 8.8, indicating a high‑severity flaw. Following remediation, the attack vector has been reproduced and is no longer exploitable, and error responses have been suppressed.
Affected Systems
The affected product is TOOOLS iSquad, a service operated by Toools S.L. The vendor released a patch that has been deployed across all production instances, and no specific version details are disclosed in the advisory.
Risk and Exploitability
Before the fix, a malicious actor could deliver SQL syntax through the limit_videos parameter to trigger database syntax errors or potentially manipulate queries. The high CVSS score reflected this risk, but the exploitation is now impossible after the vendor’s updates. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known, ongoing exploitation. The remaining risk is therefore negligible for end users relying on the patched production instances.
OpenCVE Enrichment