CVE 9.3 CRITICAL

Out-of-band SQL injection in Quatuor Performance Evaluation_CVE-2026-1479

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Description

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameters 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_ver_auto.asp', could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.

Basic Information

ID CVE-2026-1479
Source INCIBE
Published Jan 27, 2026 at 16:31

Affected Product

Vendor Quatuor
Product Evaluación de Desempeño (EDD)
Version All versions
Affected Versions Quatuor Evaluación de Desempeño (EDD) All versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.