SQL Injection in the Integratec Application
Integratec App .
INCIBE has coordinated the disclosure of a critically severe vulnerability affecting the Integratec application, a talent and human resources management platform. The vulnerability was discovered by Christopher Alejandro (Moroco).
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:
- CVE-2026-13695: CVSS v4.0: 9.1 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N | CWE-89
No solution has been reported at this time.
CVE-2026-13695: SQL injection (SQLi) vulnerability—specifically a UNION-based vulnerability—in the Integratec application that affects the sInfo parameter sent via POST to the endpoint /login/ap_Login.aspx/start. Successful exploitation of this vulnerability could allow an attacker to steal data from the database, such as credentials and user information, and cause errors and partial denial-of-service conditions. Furthermore, this vulnerability could facilitate other types of follow-up attacks, such as data exfiltration or privilege escalation.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-13695 | Crítica | No | Integratec |


