Junglewise Threat Intelligence

CVE-2026-5823: itsourcecode Construction Management System SQL injection in borrowed_tool_report.php

CVE-2026-5823 · Severity: medium · CVSS 6.3 · Published 2026-04-09

Technologies: Itsourcecode Construction Management System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Construction Management System, a software platform used for managing construction projects and tool inventory. An attacker with basic user credentials can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive project data, tampering with records, or disruption of business operations.

Technical details

A SQL injection vulnerability exists in itsourcecode Construction Management System 1.0 within the /borrowed_tool_report.php file. The root cause is the improper sanitization of the 'start' POST parameter (erroneously referred to as 'Home' in some initial reports). An authenticated attacker can provide malicious SQL payloads to perform error-based or time-based blind SQL injection. This allows for unauthorized database enumeration, data extraction, and potential system compromise. A public exploit (PoC) using sqlmap has been disclosed. No official patch is currently documented; users are advised to implement prepared statements and input validation.

Affected products

  • itsourcecode Construction Management System 1.0

Timeline

  • 2026-03-25: disclosed: Vulnerability details and PoC shared on GitHub.
  • 2026-04-09: advisory: CVE-2026-5823 published.

References

Related threats