SQL Injection Vulnerability in ITFlow Documentation and Ticketing System by ITFlow
CVE-2026-54597

8.3HIGH

Key Information:

Vendor

Itflow-org

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54597?

The vulnerability in ITFlow allows authenticated users with certain permissions to exploit a SQL injection flaw via the 'expires' parameter in the share_generate_link handler. This occurs when an unquoted input is directly inserted into a MySQL INTERVAL expression, leading to the possibility of executing conditional queries. Through this method, attackers can infer results based on response times, risking exposure of sensitive information such as password hashes, SMTP credentials, API keys, and other confidential data. It poses a significant threat to database integrity and could facilitate unauthorized access if credentials are compromised. The issue has been rectified in version 26.07.

Affected Version(s)

itflow < 26.07

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.