ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the share_generate_link handler in agent/ajax.php. sanitizeInput applies string-context escaping, but expires is inserted unquoted into the item_expire_at MySQL INTERVAL expression, allowing a crafted expression and interval unit to execute conditional database queries whose results are inferred from response delays. This can expose password hashes, SMTP credentials, API keys, encrypted vault data, and database metadata and support administrative takeover after credential cracking. This issue is fixed in version 26.07.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC for CVE-2026-54597 affecting ITFlow. It contains two files: a README with vulnerability context and usage, and a single Python entry point, exploit.py, implementing the attack logic. The exploit is not part of a larger framework. The Python script performs an authenticated web attack against ITFlow’s share link generation functionality. It logs into /login.php with supplied credentials, fetches /agent/clients.php to scrape a CSRF token and derive a client_id, then repeatedly calls /agent/ajax.php with crafted GET parameters. The vulnerable parameter is expires, which is populated with a payload of the form IF((condition),SLEEP(2),0) HOUR. The script measures response latency to determine whether injected SQL predicates evaluate true, making this a time-based blind SQL injection exploit. Capabilities include validating that the injection is live, determining output lengths, and extracting query results character-by-character using binary search over printable ASCII. Built-in extraction routines target sensitive values from the backend database: the admin password hash from users.user_password, SMTP password from settings.config_smtp_password, admin email from users.user_email, plus MySQL metadata via user() and VERSION(). The script supports selective extraction flags or an --all mode. Operationally, the exploit requires valid authentication and a valid credential/item ID on the target. It includes basic session recovery by prompting for re-authentication if the session expires or redirects to login. This is a real exploit PoC with a hardcoded SQL timing payload and practical data-exfiltration functionality, making it operational rather than a simple detector.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.