Impact
The vulnerability resides in an unknown function within the del.php file of itsourcecode Construction Management System. By manipulating the query string parameter equipname, an attacker can inject arbitrary SQL statements. This can lead to unauthorized reading, modification, or deletion of database content, thereby compromising confidentiality and integrity of the system’s data. The weakness corresponds to CWE-74 and CWE-89, indicating improper handling of string data and unsanitized input used within SQL queries.
Affected Systems
The affected product is itsourcecode Construction Management System version 1.0. No additional version details are provided, so any deployment of this system that includes the del.php component may be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity level. The absence of an EPSS score and lack of inclusion in CISA’s KEV catalog suggest that the exploitation probability is not yet well quantified, but the public availability of an exploit and the remote nature of the attack vector increase the likelihood of real-world attacks. Once exploited, the attacker can potentially manipulate or exfiltrate sensitive data stored in the system’s database.
OpenCVE Enrichment