Back

CRITICAL

SQL injection vulnerability in the Innovación y Cualificación IcProgreso plugin

Published Mar 17, 2025

Description

SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php.

Affected products

Remediation

Vendor solution

Innovación y Cualificación has released a new version that fixes the vulnerabilities detected in the affected plugins. It has been implemented in all installations of the affected software, and the process will be completed in December 2024.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCIBE
Published Mar 17, 2025
Updated Mar 18, 2025
Reserved Mar 11, 2025

CISA Vulnrichment

Updated Mar 17, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCIBE
Published Mar 17, 2025
Updated Mar 18, 2025

GitHub

No data