Security Advisory
CVE-2026-1480
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter Id_usuario in /evaluacion_objetivos_anyo_sig_evalua.aspx, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.