Impact
A SQL injection flaw exists in the borrowed_equip_report.php module of itsourcecode Construction Management System 1.0. By manipulating the Home parameter, an attacker can craft SQL statements that the application executes, enabling unauthorized reading or modification of database data. The weakness is associated with unsanitized input handling and raw SQL execution.
Affected Systems
Itsourcecode Construction Management System version 1.0 is affected. No other products or versions are listed as impacted.
Risk and Exploitability
The vulnerability carries a moderate severity score, and no public exploitation trend is recorded. It can be triggered remotely via a crafted HTTP request to borrowed_equip_report.php. An attacker who succeeds can gain read or write access to the database, potentially exposing or corrupting sensitive information. The issue is not catalogued as a known exploited vulnerability.
OpenCVE Enrichment