Junglewise Threat Intelligence

CVE-2026-81677: TOOOLS iSquad SQL injection in /ws/apiprensa/getVideo

CVE-2026-81677 · Severity: info · CVSS 8.8 · Published 2026-08-27

Technologies: TOOOLS iSquad. Vendors: TOOOLS.

Executive brief

iSquad is a cross-platform sports analytics platform used for comprehensive sports management. The '/ws/apiprensa/getVideo' endpoint accepts unsanitized user input in the `id_ambito` parameter and directly incorporates it into SQL queries, allowing attackers to inject SQL commands. An exploit could expose sensitive database information, corrupt analytics records, or enable unauthorized data access.

Technical details

CVE-2026-81677 is a SQL injection vulnerability (CWE-89) in TOOOLS' iSquad REST API endpoint '/ws/apiprensa/getVideo'. The GET parameter `id_ambito` is incorporated directly into MariaDB queries without sanitization or prepared statements. Attackers can inject SQL syntax to break the query structure, triggering database errors and exposing PDOException error messages and internal query logic. The vulnerability is network-accessible, requires no authentication or user interaction, and enables information disclosure and potential query manipulation. The vendor has deployed patches across all production instances; no client action is required.

Affected products

  • TOOOLS iSquad versions prior to the one released on July 22, 2026

Timeline

  • 2026-08-27: disclosed
  • 2026-07-22: patched: Vendor deployed fixes across all production instances

References

Related threats