CVE-2026-5660: itsourcecode Construction Management System Parameter borrowed_equip.php sql injection
A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5660?
CVE-2026-5660 is classified as a high-severity SQL injection vulnerability.
What systems are affected by CVE-2026-5660?
CVE-2026-5660 affects version 1.0 of the itsourcecode Construction Management System.
How do I fix CVE-2026-5660?
To fix CVE-2026-5660, validate and sanitize inputs in the borrowed_equip.php file to prevent SQL injection.
What kind of attack can CVE-2026-5660 enable?
CVE-2026-5660 can enable attackers to execute arbitrary SQL commands in the database.
Is CVE-2026-5660 easy to exploit?
Yes, CVE-2026-5660 is considered easy to exploit due to insufficient input validation.