CVE-2026-5823General

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the argument Home causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-09)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-08: 1Mentions · 2026-04-09: 3Technical Details · 2026-04-09: 104-0804-09
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-081
General1
2026-04-093
Disclosure2General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5823 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5823 #CVE-2026-5823 #CVE #Medium #CyberSecurity #InfoSec https://t.co/ylOcGhRdKL

    Post summary

    The tweet merely announces CVE-2026-5823 with a medium severity rating and includes a NVD link, but provides no deeper technical, exploit, or mitigation information.

    0000027
    123 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5823 SQL Injection in itsourcecode Construction Management System 1.0 /borrowed_tool_report.php https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5823

    Post summary

    The post announces a SQL Injection vulnerability in itsourcecode Construction Management System 1.0, providing basic technical details but lacking exploitation or mitigation information.

    0000044
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5823 A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_repor… https://www.cve.org/CVERecord?id=CVE-2026-5823 ----- Traducción: CVE-2026-5823 Se … http://infoflow.cloud`

    Post summary

    A new CVE-2026-5823 has been announced for Construction Management System 1.0, with a link to the official CVE record, but no additional technical details, patches, or exploitation information are provided.

    0000030
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5823 A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_repor… https://www.cve.org/CVERecord?id=CVE-2026-5823

    Post summary

    The post references a newly identified weakness in Construction Management System 1.0 (CVE-2026-5823), providing only a link to the official CVE record without additional technical details, PoC, or patch information.

    00000246
    57.0K followersView on X

Explore more