Description
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the share_generate_link handler in agent/ajax.php. sanitizeInput applies string-context escaping, but expires is inserted unquoted into the item_expire_at MySQL INTERVAL expression, allowing a crafted expression and interval unit to execute conditional database queries whose results are inferred from response delays. This can expose password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata and support administrative takeover after credential cracking. This issue is fixed in version 26.07.
Published: 2026-09-17
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft and Administrative Takeover
Action: Immediate Patch
AI Analysis

Impact

An authenticated time‑based blind SQL injection flaw exists in ITFlow before version 26.07. The vulnerability is triggered via the expires parameter in the share_generate_link handler within agent/ajax.php. The application's sanitizeInput function performs string‑context escaping, but expires is inserted unquoted into a MySQL INTERVAL expression. This allows an attacker to craft expressions that cause conditional database queries whose results are inferred from timing delays. As a result, credential data such as password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata can be retrieved, potentially giving an attacker the ability to crack credentials and take over administrative functions.

Affected Systems

ITFlow by itflow‑org is affected in all releases before 26.07. The vulnerability requires an authenticated user who holds module_support write permission and can access a credential record. Version 26.07, released on GitHub, contains the fix and removes the risk.

Risk and Exploitability

The CVSS score is 8.3, indicating high severity, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low exploitation probability. Attackers must be authenticated and hold specific permissions; they can exploit the flaw through timing analysis of response delays. Once credential information is obtained, attackers may perform credential cracking and compromise administrative accounts, leading to full control of the system.

Generated by OpenCVE AI on September 19, 2026 at 00:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ITFlow to version 26.07 or later where the issue is fixed.
  • Restrict module_support write permission and access to credential records to trusted administrators only.
  • Enforce least privilege by removing unnecessary credential record access for non‑admin users.

Generated by OpenCVE AI on September 19, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Itflow
Itflow itflow
Vendors & Products Itflow
Itflow itflow

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the share_generate_link handler in agent/ajax.php. sanitizeInput applies string-context escaping, but expires is inserted unquoted into the item_expire_at MySQL INTERVAL expression, allowing a crafted expression and interval unit to execute conditional database queries whose results are inferred from response delays. This can expose password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata and support administrative takeover after credential cracking. This issue is fixed in version 26.07.
Title ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T13:26:07.177Z

Reserved: 2026-06-15T19:45:23.539Z

Link: CVE-2026-54597

cve-icon Vulnrichment

Updated: 2026-09-18T13:25:57.649Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:16.830

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:15:13Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')