Impact
An authenticated time‑based blind SQL injection flaw exists in ITFlow before version 26.07. The vulnerability is triggered via the expires parameter in the share_generate_link handler within agent/ajax.php. The application's sanitizeInput function performs string‑context escaping, but expires is inserted unquoted into a MySQL INTERVAL expression. This allows an attacker to craft expressions that cause conditional database queries whose results are inferred from timing delays. As a result, credential data such as password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata can be retrieved, potentially giving an attacker the ability to crack credentials and take over administrative functions.
Affected Systems
ITFlow by itflow‑org is affected in all releases before 26.07. The vulnerability requires an authenticated user who holds module_support write permission and can access a credential record. Version 26.07, released on GitHub, contains the fix and removes the risk.
Risk and Exploitability
The CVSS score is 8.3, indicating high severity, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low exploitation probability. Attackers must be authenticated and hold specific permissions; they can exploit the flaw through timing analysis of response delays. Once credential information is obtained, attackers may perform credential cracking and compromise administrative accounts, leading to full control of the system.
OpenCVE Enrichment