CVE-2026-7075: itsourcecode Construction Management System locations.php sql injection
A vulnerability was found in itsourcecode Construction Management System 1.0. This issue affects some unknown processing of the file /locations.php. Performing a manipulation of the argument address results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7075?
CVE-2026-7075 has a critical severity rating due to the potential for SQL injection, allowing attackers to manipulate the database.
How do I fix CVE-2026-7075?
To fix CVE-2026-7075, sanitize and validate all user inputs for the '/locations.php' file, specifically the 'address' argument to prevent SQL injection.
What software is affected by CVE-2026-7075?
CVE-2026-7075 affects the itsourcecode Construction Management System version 1.0.
What type of attack is described in CVE-2026-7075?
CVE-2026-7075 describes an SQL injection attack that occurs through manipulation of the address argument in the locations.php file.
Can CVE-2026-7075 lead to data compromise?
Yes, CVE-2026-7075 can lead to data compromise allowing attackers to access or manipulate sensitive information in the database.