CVE-2026-5675 is a SQL injection vulnerability in itsourcecode Construction Management System version 1.0, specifically within the parameter handler of the /borrowed_tool.php file. The flaw exists in the emp argument, which fails to properly sanitize user input before processing database queries. The vulnerability carries a CVSS 3.1 score of 6.3 (Medium severity) and can be exploited remotely by authenticated users with low attack complexity. A successful exploitation could result in partial compromise of data confidentiality and integrity, as well as limited availability impact. The FAUCET Risk Score of 35.0/100 indicates moderate concern within the threat landscape. While exploit code has been publicly disclosed, the vulnerability currently shows no evidence of active exploitation in the wild, with an exceptionally low EPSS score of 0.000310000. The vulnerability is not included on CISA's Known Exploited Vulnerabilities list and remains inactive on the Hot List, suggesting limited community attention at present. Organizations running this software should apply patches when available and consider implementing input validation controls as a compensating measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Itsourcecode | Construction Management System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.