PT-2026-29325 · Oretnom23 · Alton Management System
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Loan Management System version 1.0
Description
A business logic issue exists due to improper server-side validation. The application allows administrators to create loan plans with specific interest rates. Although the frontend prevents the entry of negative numbers, this constraint is not enforced on the backend. An authenticated attacker can bypass client-side restrictions by manipulating the HTTP POST request to submit a negative value for the
interest percentage variable, leading to the creation of loan plans with negative interest rates.Recommendations
Update SourceCodester Loan Management System version 1.0 to a version that implements proper server-side validation for the
interest percentage variable.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alton Management System