Executive brief
iSquad is a cross-platform sports analytics software used for comprehensive sports management with Big Data and AI capabilities. A SQL injection vulnerability in the '/ws/apiprensa/getVideoSubcanal' endpoint allows attackers to craft malicious input that exposes internal file paths, stack traces, and potentially compromises the underlying database, risking exposure of sensitive analytics and sports data stored in the system.
Technical details
This is a SQL injection vulnerability (CWE-89) in the '/ws/apiprensa/getVideoSubcanal' endpoint caused by improper handling of the id_video parameter. The application fails to sanitize user input before constructing SQL queries, and additionally exposes sensitive information through Slim framework error handlers. The vulnerability is network-accessible (AV:N) with no authentication or user interaction required (PR:N/UI:N). An attacker can inject SQL syntax to disrupt query execution, extract database contents, or manipulate data. The vendor has patched this vulnerability and confirmed the fix eliminates error-based SQL injection and prevents stack trace exposure.
Affected products
- TOOOLS iSquad prior to July 22, 2026
Timeline
- 2026-08-27: disclosed
- 2026-07-22: patched: Patch released and deployed across all production instances
- 2026-08-27: other: INCIBE-CERT advisory published (INCIBE-2026-587)