CVE-2026-6007: itsourcecode Construction Management System del.php sql injection
A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6007?
CVE-2026-6007 has a critical severity rating due to the potential for remote SQL injection attacks.
How do I fix CVE-2026-6007?
To fix CVE-2026-6007, validate and sanitize user inputs in the del.php file to prevent SQL injection.
What systems are affected by CVE-2026-6007?
CVE-2026-6007 affects version 1.0 of the itsourcecode Construction Management System.
Can CVE-2026-6007 lead to data breaches?
Yes, CVE-2026-6007 can lead to data breaches as SQL injection may allow attackers to access and manipulate sensitive information.
Are there any known exploits for CVE-2026-6007?
Yes, there are known exploits that leverage the SQL injection vulnerability in CVE-2026-6007.