Impact
A flaw in the Construction Management System’s borrowedtool.php file permits manipulation of an argument, causing an SQL injection vulnerability. The weakness can be exploited to run arbitrary SQL commands against the backend database, potentially exposing, modifying, or deleting data and undermining confidentiality and integrity. The vulnerability aligns with input‑related weaknesses (CWE‑74) and classic SQL injection (CWE‑89).
Affected Systems
Vendor itsourcecode’s Construction Management System, specifically version 1.0, is impacted by this flaw. The vulnerability is tied to an unknown function within the borrowedtool.php endpoint, and no other product or version information is listed.
Risk and Exploitability
With a CVSS score of 5.3, the severity is moderate, but the existence of a publicly available exploit that can be triggered remotely elevates the risk. The exploit requires network access to the web application and crafted input to the borrowedtool.php script. Though no EPSS score is available and the vulnerability is not in the CISA KEV catalog, the combination of remote reach and known exploitation capability indicates a realistic threat to organizations operating this system.
OpenCVE Enrichment