SQL Injection Vulnerability in ITFlow Documentation and Ticketing System by ITFlow
CVE-2026-54597
8.3HIGH
What is CVE-2026-54597?
The vulnerability in ITFlow allows authenticated users with certain permissions to exploit a SQL injection flaw via the 'expires' parameter in the share_generate_link handler. This occurs when an unquoted input is directly inserted into a MySQL INTERVAL expression, leading to the possibility of executing conditional queries. Through this method, attackers can infer results based on response times, risking exposure of sensitive information such as password hashes, SMTP credentials, API keys, and other confidential data. It poses a significant threat to database integrity and could facilitate unauthorized access if credentials are compromised. The issue has been rectified in version 26.07.
Affected Version(s)
itflow < 26.07
