Impact
The vulnerability is a remote SQL injection flaw in the execute1.php script of itsourcecode Construction Management System 1.0. Manipulating the code argument enables attackers to inject arbitrary SQL statements, potentially giving them unauthorised read or write access to the database. This weakness corresponds to common SQL injection weaknesses (CWE-74 and CWE-89). The impact is the loss of data confidentiality and integrity, and it could lead to modification of project records or extraction of sensitive construction data.
Affected Systems
The affected product is the Construction Management System by itsourcecode, version 1.0. No other vendor or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack can be performed from a remote environment by sending a crafted request to /execute1.php, where the argument is executed in an unparameterised SQL statement.
OpenCVE Enrichment