PT-2026-30696 · Itsourcecode · Itsourcecode Construction Management System

3025680542

·

Published

2026-04-06

·

Updated

2026-04-07

·

CVE-2026-5675

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions itsourcecode Construction Management System version 1.0
Description A SQL injection flaw exists in the Parameter Handler component of itsourcecode Construction Management System. The issue is located in the /borrowed tool.php file, specifically through manipulation of the emp argument. This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /borrowed tool.php file.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5675

Affected Products

Itsourcecode Construction Management System