Itsourcecode · Construction Management System · CVE-2026-5719
**Name of the Vulnerable Software and Affected Versions**
itsourcecode Construction Management System version 1.0
**Description**
A SQL injection flaw exists in the `/borrowedtool.php` file. A remote attacker can exploit this by manipulating the `code` argument, allowing for unauthorized database queries.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `/borrowedtool.php` file to minimize the risk of exploitation.