
CVE-2026-54597 - Authenticated Time-Based Blind SQL Injection in ITFlow
Severity: High
Advisory: GHSA-m63v-j7fw-hq2h
Affected: ITFlow (agent/ajax.php — expires parameter)
Fixed in: Commit 63d8691
Author: iltosec
A time-based blind SQL injection vulnerability in ITFlow's share link generation
handler. The expires GET parameter is passed directly into a MySQL INTERVAL
expression without numeric validation, allowing authenticated users to exfiltrate
arbitrary data from the database.
Full write-up: CVE-2026-54597: Authenticated Time-Based Blind SQL Injection in ITFlow
python exploit.py http://itflow.com [email protected] 'emsJ_;PD@@;-r>4' 1
