漏洞情报聚合

CVE-2026-81676 - A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of th - 漏洞详情

漏洞编号:CVE-2026-81676

风险等级:未知

漏洞来源:CVE

CVE 编号:CVE-2026-81676

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-89

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate backend queries. The issue results in an error-based SQL injection and exposes internal database error messages and stack traces, revealing implementation details of the backend system.

相关链接

相关漏洞

« 返回首页