Security Advisory

CVE-2026-1479

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-27 16:31:06
Last updated 2026-01-27 18:57:32
Assigner INCIBE
State PUBLISHED

Description

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameters Id_usuario and Id_evaluacion’ in ‘/evaluacion_hca_ver_auto.asp, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.