PT-2026-31868 · Itsourcecode · Construction Management System

Ifan

·

Published

2026-04-10

·

Updated

2026-04-10

·

CVE-2026-6007

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-6007

Affected Products

Construction Management System