


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in itsourcecode Construction Management System 1.0. This vulnerability affects unknown code of the file /execute1.php. Such manip…
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 19:18:12
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been discovered in itsourcecode Construction Management System version 1.0. The vulnerability affects the /execute1.php file through manipulation of the 'code' argument. This attack can be performed remotely and the exploit has been publicly disclosed. The vulnerability allows remote attackers to manipulate SQL queries through improper input validation. This creates significant security risks as attackers can potentially access, modify, or delete database information.
Technical details
Mitigation steps:
Affected products:
itsourcecode Construction Management System 1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7074
https://github.com/Beatriz-ai-boop/cve/issues/3
https://itsourcecode.com/
https://vuldb.com/submit/799544
https://vuldb.com/vuln/359649
https://vuldb.com/vuln/359649/cti
Related CVE's:
Related threat actors:
IOC's:
/execute1.php
This article was created with the assistance of AI technology by Perceptive.
