An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter ‘Id_usuario' in ‘/evaluacion_acciones_evalua.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/out-band-sql-injection-quatuor-performance-evaluation | Third Party Advisory |
Configurations
History
10 Feb 2026, 20:20
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Quatuor evaluacion De Desempeno
Quatuor |
|
| References | () https://www.incibe.es/en/incibe-cert/notices/aviso/out-band-sql-injection-quatuor-performance-evaluation - Third Party Advisory | |
| CPE | cpe:2.3:a:quatuor:evaluacion_de_desempeno:-:*:*:*:*:*:*:* |
27 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-27 17:16
Updated : 2026-02-10 20:20
NVD link : CVE-2026-1475
Mitre link : CVE-2026-1475
CVE.ORG link : CVE-2026-1475
JSON object : View
Products Affected
quatuor
- evaluacion_de_desempeno
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
