Description
A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Published: 2026-04-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection enabling unauthorized database access
Action: Patch Now
AI Analysis

Impact

A flaw in the Construction Management System’s borrowedtool.php file permits manipulation of an argument, causing an SQL injection vulnerability. The weakness can be exploited to run arbitrary SQL commands against the backend database, potentially exposing, modifying, or deleting data and undermining confidentiality and integrity. The vulnerability aligns with input‑related weaknesses (CWE‑74) and classic SQL injection (CWE‑89).

Affected Systems

Vendor itsourcecode’s Construction Management System, specifically version 1.0, is impacted by this flaw. The vulnerability is tied to an unknown function within the borrowedtool.php endpoint, and no other product or version information is listed.

Risk and Exploitability

With a CVSS score of 5.3, the severity is moderate, but the existence of a publicly available exploit that can be triggered remotely elevates the risk. The exploit requires network access to the web application and crafted input to the borrowedtool.php script. Though no EPSS score is available and the vulnerability is not in the CISA KEV catalog, the combination of remote reach and known exploitation capability indicates a realistic threat to organizations operating this system.

Generated by OpenCVE AI on April 7, 2026 at 10:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch for Construction Management System 1.0
  • Restrict the database user account to the minimum privileges required by the application
  • Modify borrowedtool.php to use prepared statements or validate user input to eliminate SQL injection
  • Configure a web application firewall or database activity monitoring to block suspicious SQL queries

Generated by OpenCVE AI on April 7, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode construction Management System
Vendors & Products Itsourcecode
Itsourcecode construction Management System

Tue, 07 Apr 2026 07:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Title itsourcecode Construction Management System borrowedtool.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Construction Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-07T13:27:03.584Z

Reserved: 2026-04-06T20:02:32.469Z

Link: CVE-2026-5719

cve-icon Vulnrichment

Updated: 2026-04-07T13:26:56.732Z

cve-icon NVD

Status : Deferred

Published: 2026-04-07T03:16:08.300

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-5719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:50:13Z

Weaknesses