Out-of-band SQL injection in Quatuor Performance Evaluation
Evaluación de Desempeño (EDD).
INCIBE has coordinated the publication of 12 critical severity vulnerabilities affecting Quatuor's Performance Assessment, an assessment tool for companies. The vulnerabilities were discovered by Óscar Atienza Vendrell.
These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type for each vulnerability:
- from CVE-2026-1472 to CVE-2026-1483: CVSS v4.0: 9.3 | CVSS:4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N | CWE-89
The vulnerabilities have been resolved in the latest version of the application, released on November 12, 2025, and are no longer exploitable.
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación.
Exploiting this vulnerability could allow an attacker to extract sensitive information from the database through external channels, without the affected application returning the data directly, compromising the confidentiality of the stored information.
The list of parameters and assigned identifiers is as follows:
- CVE-2026-1472: parameter 'txAny' en '/evaluacion_competencias_autoeval_list.aspx';
- CVE-2026-1473: parameter 'Id_usuario’ en '/evaluacion_competencias_evalua.aspx';
- CVE-2026-1474: parameter 'Id_usuario' e 'Id_evaluacion' en ‘/evaluacion_inicio.aspx’;
- CVE-2026-1475: parameter ‘Id_usuario' en ‘/evaluacion_acciones_evalua.aspx’;
- CVE-2026-1476: parameter 'Id_usuario' en ‘/evaluacion_acciones_ver_auto.aspx’;
- CVE-2026-1477: parameter 'Id_usuario' e 'Id_evaluacion’ en ‘/evaluacion_competencias_evalua_old.aspx’;
- CVE-2026-1478: parameter 'Id_usuario' e 'Id_evaluacion’ en ‘/evaluacion_hca_evalua.aspx’;
- CVE-2026-1479: parameters 'Id_usuario' e 'Id_evaluacion’ en ‘/evaluacion_hca_ver_auto.asp';
- CVE-2026-1480: parameter 'Id_usuario' en '/evaluacion_objetivos_anyo_sig_evalua.aspx';
- CVE-2026-1481: parameter 'Id_usuario' en '/evaluacion_objetivos_anyo_sig_ver_auto.aspx';
- CVE-2026-1482: parameter 'Id_evaluacion' en '/evaluacion_objetivos_evalua_definido.aspx';
- CVE-2026-1483: parameter 'Id_usuario' en '/evaluacion_objetivos_ver_auto.aspx'.



