Quatuor Performance Evaluation Out-of-Band SQL Injection Vulnerability
Vulnerability
A critical out-of-band SQL injection vulnerability has been identified in the Performance Evaluation (EDD) application by Gabinete Técnico de Programación. The vulnerability exists in the 'txAny' parameter of '/evaluacion_competencias_autoeval_list.aspx'. Exploiting this flaw could enable an attacker to extract sensitive database information through external channels, bypassing direct application response and compromising data confidentiality.
Impact
Exploitation allows for unauthorized database access, enabling attackers to extract sensitive information, thereby violating data confidentiality.
Remediation
The vulnerability has been addressed in the latest version of the application, released on November 12, 2025.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
