Description
A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-04-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote data compromise via SQL injection
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Construction Management System 1.0 allows an attacker to manipulate the Name argument in the /equipments.php page. The input is directly incorporated into a SQL query, giving the attacker the ability to inject arbitrary SQL statements. This can lead to unauthorized read, modification, or deletion of the system database, potentially exposing sensitive business and client information.

Affected Systems

The vulnerability affects the itsourcecode Construction Management System, version 1.0. No other versions are listed, so the impact is confined to installations of this specific product and version.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate severity. No EPSS score is available, and the issue is not in the CISA KEV catalog, though it has been publicly disclosed. The exploit can be triggered remotely via the web interface, so any environment exposing the application to the internet is at risk. If the attacker can reach the vulnerable endpoint, exploitation likely succeeds on systems that do not employ additional mitigations such as input validation or a web application firewall.

Generated by OpenCVE AI on April 13, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor patch or upgrade to a newer, secure version of itsourcecode Construction Management System
  • Restrict access to the /equipments.php endpoint using firewall rules or IP whitelisting
  • Implement input validation or switch to parameterized queries to block SQL injection attempts
  • Deploy a web application firewall to detect and block malicious SQL payloads
  • Enforce least privilege on database accounts and monitor logs for suspicious activity

Generated by OpenCVE AI on April 13, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode construction Management System
Vendors & Products Itsourcecode
Itsourcecode construction Management System

Mon, 13 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title itsourcecode Construction Management System equipments.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Construction Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-14T19:37:43.372Z

Reserved: 2026-04-13T08:38:27.369Z

Link: CVE-2026-6191

cve-icon Vulnrichment

Updated: 2026-04-14T19:35:48.501Z

cve-icon NVD

Status : Deferred

Published: 2026-04-13T17:16:32.137

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-6191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:33:57Z

Weaknesses