Impact
An SQL injection flaw exists in itsourcecode Construction Management System 1.0, specifically when the address argument in the /locations.php script is manipulated. This flaw enables an attacker to execute arbitrary SQL statements against the underlying database from a remote location, which can lead to exposure, modification, or deletion of project data and compromise confidentiality, integrity, and availability.
Affected Systems
The affected product is itsourcecode Construction Management System version 1.0. The exact patch level or equivalent versions are not disclosed; only version 1.0 is known to be vulnerable.
Risk and Exploitability
The CVSS score of 6.9 classifies the weakness as medium severity. An EPSS score of less than 1% indicates that real‑world exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the attack vector is remote and a public exploit exists, the risk remains non‑negligible. Exploitation requires sending a specially crafted address parameter to the web application; it does not require authentication or privileged access, making it broadly exploitable by unauthenticated attackers.
OpenCVE Enrichment