Description
A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the argument Home causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-04-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Patch
AI Analysis

Impact

A flaw in itsourcecode Construction Management System version 1.0 allows manipulation of the Home argument in /borrowed_tool_report.php to inject arbitrary SQL. This vulnerability can be exploited remotely, potentially enabling attackers to alter, delete, or read database contents, thereby compromising confidentiality, integrity, and availability of project data.

Affected Systems

The critical component affected is itsourcecode Construction Management System, specifically the borrowed_tool_report.php endpoint on version 1.0. No additional vendor or product versions are listed in the data.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. Exploitation is feasible from the network per the description, and an exploit has already been made publicly available, although no EPSS value is listed. The vulnerability is not included in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Attackers can leverage the remote web interface to inject SQL, but would require some application context to construct the payload.

Generated by OpenCVE AI on April 9, 2026 at 00:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s website or support channels for an updated version or patch that addresses the SQL injection flaw.
  • If no patch is available, implement input validation or parameterized queries for the Home argument in /borrowed_tool_report.php to prevent injection.
  • Restrict access to borrowed_tool_report.php to authenticated and authorized users only, preferably through role‑based access controls.
  • Monitor web application logs for unusual query patterns or repeated failed login attempts that could indicate an attempt to exploit the injection point.

Generated by OpenCVE AI on April 9, 2026 at 00:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode construction Management System
Vendors & Products Itsourcecode
Itsourcecode construction Management System

Wed, 08 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the argument Home causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Title itsourcecode Construction Management System borrowed_tool_report.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Construction Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-08T23:30:14.821Z

Reserved: 2026-04-08T16:47:26.009Z

Link: CVE-2026-5823

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-09T00:16:21.087

Modified: 2026-04-09T00:16:21.087

Link: CVE-2026-5823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:25:27Z

Weaknesses