An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_evaluacion' in '/evaluacion_objetivos_evalua_definido.aspx', could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/out-band-sql-injection-quatuor-performance-evaluation | Third Party Advisory |
Configurations
History
10 Feb 2026, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.incibe.es/en/incibe-cert/notices/aviso/out-band-sql-injection-quatuor-performance-evaluation - Third Party Advisory | |
| CPE | cpe:2.3:a:quatuor:evaluacion_de_desempeno:-:*:*:*:*:*:*:* | |
| First Time |
Quatuor evaluacion De Desempeno
Quatuor |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
27 Jan 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-27 17:16
Updated : 2026-02-10 20:19
NVD link : CVE-2026-1482
Mitre link : CVE-2026-1482
CVE.ORG link : CVE-2026-1482
JSON object : View
Products Affected
quatuor
- evaluacion_de_desempeno
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
