PT-2026-29324 · Oretnom23 · Alton Management System

·

CVE-2026-30520

·

Published

2026-03-31

·

Updated

2026-03-31

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Loan Management System version 1.0
Description An authenticated attacker can perform a Blind SQL Injection, a technique used to extract information from a database by asking true or false questions. The issue occurs in the 'ajax.php' file within the save loan action because the application does not properly sanitize the borrower id parameter in POST requests.
Recommendations Update SourceCodester Loan Management System version 1.0 to a version where the borrower id parameter in the save loan action of 'ajax.php' is properly sanitized.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30520

Affected Products

Alton Management System