CNNVD-202601-4504 Information
Jan 27, 2026
cve
CNNVD ID
CNNVD-202601-4504
Related CVE
- CNNVD Published: 2026-01-27
Description (Chinese)
Quatuor Evaluación de Desempeño是西班牙Quatuor公司的一个绩效评估系统。 Quatuor Evaluación de Desempeño存在SQL注入漏洞,该漏洞源于文件/evaluacion_competencias_evalua_old.aspx中参数Id_usuario和Id_evaluacion存在带外SQL注入,可能导致数据库敏感信息泄露。
Description (English)
Quatuor Evaluación de Desempeño is a performance appraisal system of the Spanish company Quatuor. Quatuor Evaluación de Desempeño has a SQL-injected loophole, which stems from the external SQL injection of Id usuario and Id evaluación, the parameters of document/evaluacion competencias evalua old.aspx, which may lead to the leakage of sensitive information from the database.
Hazard Level
Low
Vulnerability Type
SQL注入
Affected Vendor
Quatuor
Published
2026-01-27
Last Modified
2026-02-24