CNNVD-202601-4498 Information
Jan 27, 2026
cve
CNNVD ID
CNNVD-202601-4498
Related CVE
- CNNVD Published: 2026-01-27
Description (Chinese)
Quatuor Evaluación de Desempeño是西班牙Quatuor公司的一个绩效评估系统。 Quatuor Evaluación de Desempeño存在SQL注入漏洞,该漏洞源于对文件/evaluacion_objetivos_ver_auto.aspx中参数Id_usuario的错误操作,可能导致带外SQL注入攻击,泄露数据库敏感信息。
Description (English)
Quatuor Evaluación de Desempeño is a performance appraisal system of the Spanish company Quatuor. Quatuor Evaluación de Desempeño has an injection loophole in SQL, which stems from a mishandling of the parameter Id usuario in document/evaluacion objetivos ver auto.aspx, which may lead to external SQL injections and leaks sensitive database information.
Hazard Level
Low
Vulnerability Type
SQL注入
Affected Vendor
Quatuor
Published
2026-01-27
Last Modified
2026-02-24