云虫漏洞库

CVE-2026-81672 - SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The vulnerability exposes internal file paths and complete stack traces through the Slim framework’s error handler, which increases the severity due to the combination of information disclosure and SQL injection. - 漏洞详情

漏洞编号:CVE-2026-81672

风险等级:未知

漏洞来源:CVE

CVE 编号:CVE-2026-81672

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-89

发布/更新时间:2026-08-27 / 2026-08-28

漏洞描述

SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The vulnerability exposes internal file paths and complete stack traces through the Slim framework’s error handler, which increases the severity due to the combination of information disclosure and SQL injection.

相关链接

相关漏洞

« 返回首页