CVE-2026-5719 is a SQL injection vulnerability identified in itsourcecode Construction Management System version 1.0, specifically within the /borrowedtool.php file's code parameter. The flaw allows authenticated attackers to manipulate input arguments and execute arbitrary SQL commands against the underlying database. This vulnerability affects the confidentiality, integrity, and availability of the application and its data. The vulnerability carries a CVSS v3.1 score of 6.3 (Medium severity) with a network-based attack vector requiring low complexity and valid user credentials, but no user interaction. The attack is remotely exploitable by authenticated users and could result in unauthorized data access, modification, or denial of service. The FAUCET Risk Score of 44.0 out of 100 indicates moderate concern within the vulnerability landscape. While exploit code has been publicly disclosed, the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows minimal real-world exploitation activity based on its low EPSS score of 0.0001. Community attention appears limited, suggesting the vulnerability primarily affects organizations running this specific construction management system. Organizations using this software should prioritize patching or implementing input validation controls to prevent exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Itsourcecode | Construction Management System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.