Description
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by agent/post/recurring_invoice.php. The handler passes recurring_invoice_frequency through sanitizeInput but interpolates it unquoted into DATE_ADD, allowing SQL syntax to escape the interval expression, assign additional INSERT columns, store subquery results in recurring_invoice_note, and expose those results through agent/recurring_invoice.php. The persisted recurring_invoice_frequency can execute again when Force Recurring uses it in a later UPDATE, allowing another legitimate user to trigger the second-order injection. This can expose password hashes, SMTP credentials, user records, and database metadata, modify database fields, and enable administrative takeover after credential cracking. This issue is fixed in version 26.07.
Published: 2026-09-17
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Exfiltration and Potential Administrative Takeover
Action: Immediate Patch
AI Analysis

Impact

ITFlow's recurring_invoice_frequency parameter is vulnerable to a second‑order SQL injection. An authenticated Technician with invoice access can craft a special value that bypasses the sanitizeInput filter and injects SQL into a DATE_ADD expression. This injection allows the attacker to add columns, redirect results into a note field, and ship password hashes, SMTP credentials, user records, and metadata back through a legitimate endpoint. If an older value is later reused by a legitimate user during a Force Recurring update, the injection is retriggered, enabling repeated data exfiltration or modification of critical data. The flaw permits complete read access to the database and, combined with credential cracking, full administrative takeover.

Affected Systems

Users of the open‑source ITFlow platform who are running any version older than 26.07 are affected. The vulnerability exists specifically for authenticated technicians or higher who can view at least one client invoice. All deployments using the POST endpoint agent/post/recurring_invoice.php are at risk, regardless of deployment size or location.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, and while the EPSS score is under 1%—meaning exploitation is considered unlikely when the vulnerability first appears—the low probability reflects the need for privileged credentials and a specific path. The solution is not listed in the CISA KEV catalog, reducing immediate awareness among broader security communities. The attack vector is inferred to be authenticated, web‑based exploitation through the recurring invoice interface. An attacker would need valid Technician credentials with invoice access and the ability to submit a crafted frequency value; no known public exploit references exist beyond the development commit notes.

Generated by OpenCVE AI on September 19, 2026 at 02:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ITFlow to version 26.07 or later
  • If immediate upgrade is not possible, identify and delete any recurring_invoice_frequency entries that contain SQL injection patterns to prevent second‑order exploitation.
  • Restrict or audit Technician or higher user privileges to limit access to invoice editing, reducing the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 02:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Itflow
Itflow itflow
Vendors & Products Itflow
Itflow itflow

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by agent/post/recurring_invoice.php. The handler passes recurring_invoice_frequency through sanitizeInput but interpolates it unquoted into DATE_ADD, allowing SQL syntax to escape the interval expression, assign additional INSERT columns, store subquery results in recurring_invoice_note, and expose those results through agent/recurring_invoice.php. The persisted recurring_invoice_frequency can execute again when Force Recurring uses it in a later UPDATE, allowing another legitimate user to trigger the second-order injection. This can expose password hashes, SMTP credentials, user records, and database metadata, modify database fields, and enable administrative takeover after credential cracking. This issue is fixed in version 26.07.
Title ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:46:48.125Z

Reserved: 2026-06-15T19:45:23.539Z

Link: CVE-2026-54596

cve-icon Vulnrichment

Updated: 2026-09-24T20:46:44.887Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:16.683

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-54596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')