PT-2026-35284 · Itsourcecode · Construction Management System

Willchen

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7073

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /execute.php. This manipulation of the argument code causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7073

Affected Products

Construction Management System