Aller au contenu

Fiche vulnérabilité

CVE-2026-1474 : faille élevée quatuor evaluacion de desempeno (CVSS 7.5)

Description

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion' en ‘/evaluacion_inicio.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
27 janv. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • quatuor evaluacion de desempeno

Références

Rechercher une autre vulnérabilité dans la base CVE