CVE-2026-5660General

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 104-06
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5660 A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the co… https://www.cve.org/CVERecord?id=CVE-2026-5660 ----- Traducción: CVE-2026-5660 Se … http://infoflow.cloud`

    Post summary

    The post merely reports CVE-2026-5660 and links to its CVE.org entry, offering no additional details on the vulnerability, exploit tools, or mitigation.

    0000027
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5660 A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the co… https://www.cve.org/CVERecord?id=CVE-2026-5660

    Post summary

    The post merely announces CVE‑2026‑5660 as a vulnerability in Construction Management System 1.0, pointing to an unknown function in /borrowed_equip.php, with no additional technical, exploit, or remediation details.

    00000381
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5660 SQL Injection in itsourcecode Construction Management System 1.0 Parameter Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5660

    Post summary

    The post identifies a SQL Injection issue in itsourcecode Construction Management System 1.0, providing minimal technical detail but no PoC, exploit, or mitigation information.

    0000050
    4.0K followersView on X

Explore more