CVE-2026-54597: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in itflow-org itflow
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the share_generate_link handler in agent/ajax.php. sanitizeInput applies string-context escaping, but expires is inserted unquoted into the item_expire_at MySQL INTERVAL expression, allowing a crafted expression and interval unit to execute conditional database queries whose results are inferred from response delays. This can expose password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata and support administrative takeover after credential cracking. This issue is fixed in version 26.07.
AI Analysis
Technical Summary
ITFlow, an IT documentation, ticketing, and accounting system, contains a SQL injection vulnerability (CWE-89) in versions before 26.07. The flaw exists in the share_generate_link handler in agent/ajax.php, where the expires parameter is used unquoted in a MySQL INTERVAL expression. Although sanitizeInput applies string-context escaping, it does not prevent injection in this numeric context. An authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection, enabling conditional database queries inferred from response delays. This can lead to exposure of password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata, potentially allowing administrative takeover after credential cracking. The vulnerability is addressed in version 26.07.
Potential Impact
Exploitation of this vulnerability can lead to disclosure of highly sensitive information such as password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata. This exposure can facilitate administrative account takeover following credential cracking. The vulnerability requires authenticated access with specific permissions, limiting the attack surface to authorized users with module_support write permission and access to credential records. The CVSS 3.1 score is 8.3 (high severity), reflecting the significant confidentiality and integrity impact with low attack complexity and no user interaction required.
Mitigation Recommendations
This vulnerability is fixed in itflow version 26.07. Users should upgrade to version 26.07 or later to remediate this issue. No other mitigation actions are indicated or necessary according to the available data.
CVE-2026-54597: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in itflow-org itflow
Description
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the share_generate_link handler in agent/ajax.php. sanitizeInput applies string-context escaping, but expires is inserted unquoted into the item_expire_at MySQL INTERVAL expression, allowing a crafted expression and interval unit to execute conditional database queries whose results are inferred from response delays. This can expose password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata and support administrative takeover after credential cracking. This issue is fixed in version 26.07.
CVSS v3.1
Score 8.3high
Affected software
itflow-org
itflow
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ITFlow, an IT documentation, ticketing, and accounting system, contains a SQL injection vulnerability (CWE-89) in versions before 26.07. The flaw exists in the share_generate_link handler in agent/ajax.php, where the expires parameter is used unquoted in a MySQL INTERVAL expression. Although sanitizeInput applies string-context escaping, it does not prevent injection in this numeric context. An authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection, enabling conditional database queries inferred from response delays. This can lead to exposure of password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata, potentially allowing administrative takeover after credential cracking. The vulnerability is addressed in version 26.07.
Potential Impact
Exploitation of this vulnerability can lead to disclosure of highly sensitive information such as password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata. This exposure can facilitate administrative account takeover following credential cracking. The vulnerability requires authenticated access with specific permissions, limiting the attack surface to authorized users with module_support write permission and access to credential records. The CVSS 3.1 score is 8.3 (high severity), reflecting the significant confidentiality and integrity impact with low attack complexity and no user interaction required.
Mitigation Recommendations
This vulnerability is fixed in itflow version 26.07. Users should upgrade to version 26.07 or later to remediate this issue. No other mitigation actions are indicated or necessary according to the available data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T19:45:23.539Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aac51e755bf5e2cf5e0cf17
Added to database: 09/17/2026, 20:47:35 UTC
Last enriched: 09/17/2026, 21:02:55 UTC
Last updated: 09/18/2026, 00:46:55 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.