CVE-2026-1479Disclosure(quatuor / evaluacion_de_desempeno)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameters 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_ver_auto.asp', could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • evaluacion_de_desempeno

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-01-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
evaluacion_de_desempeno

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-28: 1Mentions · 2026-08-04: 1Technical Details · 2026-01-27: 2Technical Details · 2026-01-28: 101-2701-2808-04
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure2
2026-01-281
Disclosure1
2026-08-041
General1
Full discourse4 posts
  • Seranged@Seranged
    General

    CVE-2026-1479: Critical vulnerability allows remote attacker to inject cold chips into customers order.

    Post summary

    The notice lists CVE‑2026‑1479 as a critical vulnerability that allegedly lets a remote attacker inject cold chips into customer orders, but offers no substantive technical or operational details.

    10000444
    4.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1479 Out-of-Band SQL Injection in Performance Evaluation Application via User Parameters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1479

    Post summary

    The statement announces CVE-2026-1479 as an out‑of‑band SQL injection affecting a performance evaluation application via user parameters, offering technical details but no exploit, patch, or evidence of active exploitation.

    0000069
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1479: Out-of-band SQL injection in Quat... OOB SQLi in Quatuor EDD lets attackers blind-extract DB contents via Id_usuario/Id_evaluacion params with zero auth - tr... https://zerodaysignal.com/vulnerability/CVE-2026-1479 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-1479, an out-of-band blind SQL injection in Quatuor EDD that allows unauthenticated extraction of database contents via specific parameters.

    0000068
    132 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1479 An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. E… https://www.cve.org/CVERecord?id=CVE-2026-1479

    Post summary

    The post announces the detection of CVE‑2026‑1479 as an out‑of‑band SQL injection in the EDD application, but offers no proof of exploitation, PoC, or patch information.

    00000143
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appquatuorevaluacion_de_desempeno---

Explore more