Executive brief
iSquad is a cross-platform sports analytics platform used for comprehensive sports management. The '/ws/apiprensa/getVideo' endpoint accepts unsanitized user input in the `id_ambito` parameter and directly incorporates it into SQL queries, allowing attackers to inject SQL commands. An exploit could expose sensitive database information, corrupt analytics records, or enable unauthorized data access.
Technical details
CVE-2026-81677 is a SQL injection vulnerability (CWE-89) in TOOOLS' iSquad REST API endpoint '/ws/apiprensa/getVideo'. The GET parameter `id_ambito` is incorporated directly into MariaDB queries without sanitization or prepared statements. Attackers can inject SQL syntax to break the query structure, triggering database errors and exposing PDOException error messages and internal query logic. The vulnerability is network-accessible, requires no authentication or user interaction, and enables information disclosure and potential query manipulation. The vendor has deployed patches across all production instances; no client action is required.
Affected products
- TOOOLS iSquad versions prior to the one released on July 22, 2026
Timeline
- 2026-08-27: disclosed
- 2026-07-22: patched: Vendor deployed fixes across all production instances