Executive brief
TOOOLS iSquad is a cross-platform sports analytics platform used for comprehensive sports management with Big Data and AI capabilities. A SQL injection vulnerability in the '/ws/apitribuna/ultimosVideos' endpoint allows unauthenticated remote attackers to inject malicious SQL commands through the limit_videos parameter, potentially exposing sensitive database information, manipulating queries, and disrupting analytics data integrity.
Technical details
This is an error-based SQL injection vulnerability (CWE-89) in the '/ws/apitribuna/ultimosVideos' API endpoint where the limit_videos parameter is directly concatenated into a MariaDB SQL query without sanitization or parameterization. The vulnerability is remotely exploitable over the network with no authentication or user interaction required (CVSS vector AV:N/AC:L/AT:N/PR:N/UI:N). An attacker can inject SQL syntax to cause query syntax errors, exposing internal database error messages and stack traces through the Slim framework's error handler, revealing backend implementation details. The vulnerability has been patched by TOOOLS; fixes were deployed to all production instances as of the advisory date, and internal SQL injection testing confirmed the endpoints are no longer exploitable.
Affected products
- TOOOLS iSquad prior to July 22, 2026
Timeline
- 2026-08-27: disclosed: Coordinated disclosure by INCIBE-CERT (INCIBE-2026-587)
- 2026-07-22: patched: Fix deployed to all production instances
- 2026-08-27: other: CVE-2026-81676 assigned with CVSS v4.0 score 8.8