CVE-2026-6191: itsourcecode Construction Management System equipments.php sql injection
A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6191?
CVE-2026-6191 is classified as a critical SQL injection vulnerability due to its potential to compromise the database of the affected system.
How do I fix CVE-2026-6191?
To fix CVE-2026-6191, ensure that all user inputs on the equipments.php page are properly sanitized and validated to prevent SQL injection.
What systems are affected by CVE-2026-6191?
CVE-2026-6191 affects version 1.0 of the itsourcecode Construction Management System specifically the equipments.php file.
What type of attack is possible through CVE-2026-6191?
CVE-2026-6191 allows attackers to perform SQL injection attacks by manipulating the 'Name' argument in the request.
Is there a known exploit for CVE-2026-6191?
While there may be theories of exploitation, specific publicly disclosed exploits for CVE-2026-6191 have not been recorded.