A vulnerability marked as critical has been reported in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /del1.php. This manipulation of the argument toolname causes sql injection.
This vulnerability is registered as CVE-2026-6030. Remote exploitation of the attack is possible. Furthermore, an exploit is available.