CVE-2026-5681: itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
Published Apr 6, 2026
·Updated
A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument empid causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode itsourcecode=1.0
Event History
Apr 6, 2026
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Nov 16, 58530
Event
via NVD·02:56 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-5681?
The severity of CVE-2026-5681 is medium with a score of 5.3.
2
What type of vulnerability is CVE-2026-5681?
CVE-2026-5681 is classified as an SQL injection vulnerability.
3
Can CVE-2026-5681 be exploited remotely?
Yes, CVE-2026-5681 can be exploited remotely.
4
How do I fix CVE-2026-5681?
To fix CVE-2026-5681, validate and sanitize the input parameters in the borrowedequip.php file.
5
What is the impact of CVE-2026-5681?
The impact of CVE-2026-5681 includes potential unauthorized access to the database through SQL injection.