SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.
Advisories

No advisories yet.

Fixes

Solution

No solution has been reported yet.


Workaround

No workaround given by the vendor.

History

Tue, 06 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.
Title SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies
First Time appeared Rdl Technologies
Rdl Technologies eloanapp Platform
Weaknesses CWE-89
CPEs cpe:2.3:a:rdl_technologies:eloanapp_platform:*:*:*:*:*:*:*:*
Vendors & Products Rdl Technologies
Rdl Technologies eloanapp Platform
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-06T08:19:49.785Z

Reserved: 2026-03-26T12:50:11.948Z

Link: CVE-2026-4889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:56.317

Modified: 2026-10-06T09:17:56.317

Link: CVE-2026-4889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T09:30:13Z

Weaknesses