Description
SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.
Published: 2026-10-06
Score: 7.8 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

No solution has been reported yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.
Title SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies
First Time appeared Rdl Technologies
Rdl Technologies eloanapp Platform
Weaknesses CWE-89
CPEs cpe:2.3:a:rdl_technologies:eloanapp_platform:*:*:*:*:*:*:*:*
Vendors & Products Rdl Technologies
Rdl Technologies eloanapp Platform
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L'}


Subscriptions

Rdl Technologies Eloanapp Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-06T11:42:02.159Z

Reserved: 2026-03-26T12:50:11.948Z

Link: CVE-2026-4889

cve-icon Vulnrichment

Updated: 2026-10-06T11:41:54.102Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:56.317

Modified: 2026-10-06T12:16:49.210

Link: CVE-2026-4889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T09:30:13Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')