漏洞情报聚合

CVE-2026-81677 - The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of database error messages via PDOException. This confirms that user input is being incorporated directly into SQL statements without proper sanitization or the use of prepared statements. - 漏洞详情

漏洞编号:CVE-2026-81677

风险等级:未知

漏洞来源:CVE

CVE 编号:CVE-2026-81677

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-89

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of database error messages via PDOException. This confirms that user input is being incorporated directly into SQL statements without proper sanitization or the use of prepared statements.

相关链接

相关漏洞

« 返回首页