Junglewise Threat Intelligence

CVE-2026-81672: TOOOLS iSquad SQL injection in getVideoSubcanal endpoint

CVE-2026-81672 · Severity: info · CVSS 9.3 · Published 2026-08-27

Technologies: TOOOLS iSquad. Vendors: TOOOLS.

Executive brief

iSquad is a cross-platform sports analytics software used for comprehensive sports management with Big Data and AI capabilities. A SQL injection vulnerability in the '/ws/apiprensa/getVideoSubcanal' endpoint allows attackers to craft malicious input that exposes internal file paths, stack traces, and potentially compromises the underlying database, risking exposure of sensitive analytics and sports data stored in the system.

Technical details

This is a SQL injection vulnerability (CWE-89) in the '/ws/apiprensa/getVideoSubcanal' endpoint caused by improper handling of the id_video parameter. The application fails to sanitize user input before constructing SQL queries, and additionally exposes sensitive information through Slim framework error handlers. The vulnerability is network-accessible (AV:N) with no authentication or user interaction required (PR:N/UI:N). An attacker can inject SQL syntax to disrupt query execution, extract database contents, or manipulate data. The vendor has patched this vulnerability and confirmed the fix eliminates error-based SQL injection and prevents stack trace exposure.

Affected products

  • TOOOLS iSquad prior to July 22, 2026

Timeline

  • 2026-08-27: disclosed
  • 2026-07-22: patched: Patch released and deployed across all production instances
  • 2026-08-27: other: INCIBE-CERT advisory published (INCIBE-2026-587)

References

Related threats