CVE-2026-5675 | itsourcecode Construction Management System 1.0 Parameter /borrowed_tool.php emp sql injection
A vulnerability described as critical has been identified in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection.
This vulnerability is known as CVE-2026-5675. It is possible to launch the attack remotely. Furthermore, an exploit is available.