Quatuor Performance Evaluation Out-of-Band SQL Injection Vulnerability
Vulnerability
A critical out-of-band SQL injection vulnerability has been identified in the Quatuor Performance Evaluation application, specifically in the 'Id_usuario' parameter of the '/evaluacion_competencias_evalua.aspx' page. This vulnerability allows attackers to extract sensitive database information through external channels, bypassing direct application responses and compromising data confidentiality.
Impact
Exploitation of this vulnerability could lead to unauthorized data extraction from the application's database, allowing attackers to access sensitive information without detection.
Remediation
The vulnerability has been addressed in the latest version of the application, released on November 12, 2025. Users are advised to update to this version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
