NONE · 0

CVE-2026-81674

The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject ...

Vulnerability Description

The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results in detailed database error messages and exposes the internal structure of the queries, which could facilitate further exploitation.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-81674?

CVE-2026-81674 is a documented vulnerability. The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject ...

How severe is CVE-2026-81674?

CVSS scoring is not yet available for CVE-2026-81674. Check NVD for updates.

Is there a patch for CVE-2026-81674?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.