Filtered by vendor Itsourcecode Subscriptions
Filtered by product Construction Management System Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-5675 1 Itsourcecode 1 Construction Management System 2026-04-07 6.3 Medium
A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVE-2026-5719 1 Itsourcecode 1 Construction Management System 2026-04-07 6.3 Medium
A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVE-2024-50972 2 Angeljudesuarez, Itsourcecode 2 Construction Management System, Construction Management System 2024-11-18 6.5 Medium
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
CVE-2024-50971 2 Angeljudesuarez, Itsourcecode 2 Construction Management System, Construction Management System 2024-11-18 6.5 Medium
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.