PT-2026-29325 · Oretnom23 · Alton Management System

·

CVE-2026-30521

·

Published

2026-03-31

·

Updated

2026-07-24

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Loan Management System version 1.0
Description A business logic issue exists due to improper server-side validation. The application allows administrators to create loan plans with specific interest rates. Although the frontend prevents the entry of negative numbers, this constraint is not enforced on the backend. An authenticated attacker can bypass client-side restrictions by manipulating the HTTP POST request to submit a negative value for the interest percentage variable, leading to the creation of loan plans with negative interest rates.
Recommendations Update SourceCodester Loan Management System version 1.0 to a version that implements proper server-side validation for the interest percentage variable.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30521

Affected Products

Alton Management System