PT-2026-29521 · Sourcecodester · Alton Management System

Meifukun

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-30522

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Loan Management System version 1.0
Description A business logic issue exists due to insufficient server-side validation. Administrators can create 'Loan Plans' with penalty rates for overdue payments. The frontend restricts negative values in the 'Monthly Overdue Penalty' field, but this check is absent on the backend. An attacker can bypass the client-side restriction by manipulating the HTTP POST request to submit a negative value for the penalty rate parameter.
Recommendations Ensure server-side validation is implemented for the penalty rate parameter to prevent negative values from being accepted.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-30522

Affected Products

Alton Management System