CVE-2026-6191

MEDIUM

itsourcecode Construction Management System equipments.php sql injection

Title source: cna

Description

A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 6.3
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
itsourcecode/Construction Management System 1.0
Published Apr 13, 2026
Tracked Since Apr 13, 2026