Junglewise Threat Intelligence

CVE-2026-5719: itsourcecode Construction Management System SQL injection in borrowedtool.php

CVE-2026-5719 · Severity: medium · CVSS 6.3 · Published 2026-04-07

Technologies: Itsourcecode Construction Management System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Construction Management System, a software platform used for managing construction projects. An attacker with basic user credentials can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive project data, tampering with records, or disruption of the management system's operations.

Technical details

A SQL injection vulnerability exists in itsourcecode Construction Management System 1.0 within the /borrowedtool.php component. The root cause is the application's failure to properly sanitize or validate the 'code' GET parameter before using it in a database query. An authenticated attacker can exploit this by submitting a crafted SQL payload (e.g., time-based blind injection) to manipulate queries. Successful exploitation allows for unauthorized database access, data exfiltration, and potential system control. A proof-of-concept exploit using sqlmap has been publicly disclosed.

Affected products

  • itsourcecode Construction Management System 1.0

Timeline

  • 2026-03-30: disclosed: Vulnerability details and PoC shared on GitHub issue tracker
  • 2026-04-07: advisory: NVD/VulDB advisory published

References

Related threats