SQL Injection Vulnerability in ITFlow Documentation and Ticketing System
CVE-2026-54596
8.1HIGH
What is CVE-2026-54596?
ITFlow, a tool designed for small managed service providers, has a vulnerability allowing SQL injection through the frequency parameter in recurring invoices. This issue affects authenticated users with access to client invoices prior to version 26.07. By exploiting the injection flaw, attackers can manipulate SQL queries through the poorly sanitized input, possibly leading to unauthorized access to sensitive data such as password hashes and SMTP credentials. The vulnerability can further enable attackers to perform updates and modifications within the database and could result in administrative control over the application. This flaw has been addressed in the latest release.
Affected Version(s)
itflow < 26.07
