9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Description
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_evalua.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.
Basic Information
ID
CVE-2026-1478
Source
INCIBE
Published
Jan 27, 2026 at 16:30
Affected Product
Vendor
Quatuor
Product
Evaluación de Desempeño (EDD)
Version
All versions
Affected Versions
Quatuor Evaluación de Desempeño (EDD) All versions