SQL Injection Vulnerability in itsourcecode Construction Management System 1.0
CVE-2026-7073
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 27 April 2026
Badges
What is CVE-2026-7073?
A security vulnerability has been identified in the itsourcecode Construction Management System version 1.0, which can be exploited to execute SQL injection attacks. This flaw resides in the execute.php file, where improper handling of an argument allows remote attackers to manipulate SQL queries. Exploitation of this vulnerability poses a serious risk, enabling unauthorized data access and potential database compromise. Users are advised to implement the necessary security measures and monitor for potential exploits.
Affected Version(s)
Construction Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
