CVE-2026-5675: itsourcecode Construction Management System Parameter borrowed_tool.php sql injection
A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowedtool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5675?
The severity of CVE-2026-5675 is categorized as low with a score of 2.1.
What type of vulnerability is CVE-2026-5675?
CVE-2026-5675 is classified as an SQL Injection vulnerability affecting the itsourcecode Construction Management System.
How can I exploit CVE-2026-5675?
CVE-2026-5675 can be exploited by manipulating the 'emp' parameter in the borrowed_tool.php file to execute unauthorized SQL commands.
How do I fix CVE-2026-5675?
To fix CVE-2026-5675, ensure proper input validation and use prepared statements to prevent SQL injection.
Is CVE-2026-5675 remotely exploitable?
Yes, CVE-2026-5675 is remotely exploitable due to the nature of the vulnerability.