SQL Injection in the Integratec Application

Posted date 30/09/2026
Identificador
INCIBE-2026-682
Importance
5 - Critical
Affected Resources

Integratec App .

Description

INCIBE has coordinated the disclosure of a critically severe vulnerability affecting the Integratec application, a talent and human resources management platform. The vulnerability was discovered by Christopher Alejandro (Moroco).

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:

  • CVE-2026-13695: CVSS v4.0: 9.1 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N | CWE-89
Solution

No solution has been reported at this time.

Detail

CVE-2026-13695: SQL injection (SQLi) vulnerability—specifically a UNION-based vulnerability—in the Integratec application that affects the sInfo parameter sent via POST to the endpoint /login/ap_Login.aspx/start. Successful exploitation of this vulnerability could allow an attacker to steal data from the database, such as credentials and user information, and cause errors and partial denial-of-service conditions. Furthermore, this vulnerability could facilitate other types of follow-up attacks, such as data exfiltration or privilege escalation.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-13695 Crítica No Integratec
References list