ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by agent/post/recurring_invoice.php. The handler passes recurring_invoice_frequency through sanitizeInput but interpolates it unquoted into DATE_ADD, allowing SQL syntax to escape the interval expression, assign additional INSERT columns, store subquery results in recurring_invoice_note, and expose those results through agent/recurring_invoice.php. The persisted recurring_invoice_frequency can execute again when Force Recurring uses it in a later UPDATE, allowing another legitimate user to trigger the second-order injection. This can expose password hashes, SMTP credentials, user records, and database metadata, modify database fields, and enable administrative takeover after credential cracking. This issue is fixed in version 26.07.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact, single-purpose authenticated exploit for CVE-2026-54596 in ITFlow. It contains two files: a README describing the vulnerability and usage, and a Python script (exploit.py) that implements the attack. The exploit is not part of a larger framework. The script logs into an ITFlow instance using attacker-supplied credentials, scrapes a CSRF token from authenticated agent pages, and then submits a crafted POST request to /agent/post.php. The SQL injection is delivered through the recurring invoice frequency field (sent as POST parameter frequency while triggering add_invoice_recurring=1). The payload closes the expected SQL context and injects a subquery into recurring_invoice_note so that the selected database value is rendered back in the application response. The script then parses the returned HTML note field to recover the exfiltrated value. Capabilities include: validating exploit reachability with a probe query, extracting the first admin password hash and email, extracting SMTP username/password from settings, enumerating DB metadata (current DB user, DB version, database name), and dumping all rows from the users table by first counting users and then iterating over user_name, user_email, user_type, and user_password. The exploit enforces a 200-character payload limit, suggesting awareness of application-side field constraints. Operational flow: main() parses CLI arguments, login() authenticates via /login.php, get_csrf() searches several authenticated pages for a csrf_token, fire() sends the malicious recurring invoice creation request and confirms success via recurring_invoice_id in the redirect URL, and extract_users() performs iterative table dumping. The exploit requires a valid invoice_id accessible to the authenticated user, matching the README claim that a Technician with access to at least one client invoice can exfiltrate sensitive database contents. Overall, this is a real operational web exploit for authenticated SQLi-based data exfiltration against vulnerable ITFlow deployments, not merely a detector or advisory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.