Impact
A flaw in itsourcecode Construction Management System version 1.0 allows manipulation of the Home argument in /borrowed_tool_report.php to inject arbitrary SQL. This vulnerability can be exploited remotely, potentially enabling attackers to alter, delete, or read database contents, thereby compromising confidentiality, integrity, and availability of project data.
Affected Systems
The critical component affected is itsourcecode Construction Management System, specifically the borrowed_tool_report.php endpoint on version 1.0. No additional vendor or product versions are listed in the data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploitation is feasible from the network per the description, and an exploit has already been made publicly available, although no EPSS value is listed. The vulnerability is not included in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Attackers can leverage the remote web interface to inject SQL, but would require some application context to construct the payload.
OpenCVE Enrichment