Beveiligingsadvies

CVE-2026-1474

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-27 16:27:58
Laatst bijgewerkt 2026-01-27 20:52:37
Toegewezen door INCIBE
CVSS-score 9.3
Status PUBLISHED

Beschrijving

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion' en ‘/evaluacion_inicio.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.