CVE-2026-5620: itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection
A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowedequipreport.php of the component Parameter Handler. The manipulation of the argument Home leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5620?
CVE-2026-5620 is classified as a SQL injection vulnerability which can lead to unauthorized access to sensitive data.
How do I fix CVE-2026-5620?
To fix CVE-2026-5620, validate and sanitize user inputs in the borrowed_equip_report.php file to prevent SQL injection attacks.
What systems are affected by CVE-2026-5620?
CVE-2026-5620 affects version 1.0 of the itsourcecode Construction Management System.
What type of vulnerability is CVE-2026-5620?
CVE-2026-5620 is a SQL injection vulnerability found in the parameter handler of the Construction Management System.
Can CVE-2026-5620 be exploited remotely?
Yes, CVE-2026-5620 can be exploited remotely since it involves unsanitized input handling in a web application.