Executive brief
itsourcecode Construction Management System is a web application used for managing construction projects. A security vulnerability in the tool tracking component allows an authenticated user to perform unauthorized database operations. This could lead to the exposure of sensitive project data, unauthorized modification of records, or disruption of the management system.
Technical details
A SQL injection vulnerability exists in itsourcecode Construction Management System 1.0 within the 'Parameter Handler' component of the /borrowed_tool.php file. The root cause is the improper neutralization of special elements in the 'emp' POST parameter, which is used in SQL queries without sufficient sanitization or prepared statements. An attacker with valid low-privileged credentials can exploit this via a time-based blind SQL injection attack to extract information from the database or manipulate data. A public proof-of-concept using sqlmap has been disclosed, confirming the vulnerability in the MySQL backend.
Affected products
- itsourcecode Construction Management System 1.0
Timeline
- 2026-03-29: disclosed: Initial disclosure on GitHub repository
- 2026-04-06: advisory: VulDB and NVD publication