Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 07 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Blind SQL Injection in SourceCodester Loan Management System 1.0 |
Mon, 06 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Blind SQL Injection in SourceCodester Loan Management System 1.0 |
Thu, 02 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oretnom23
Oretnom23 loan Management System |
|
| CPEs | cpe:2.3:a:oretnom23:loan_management_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Oretnom23
Oretnom23 loan Management System |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Blind SQL Injection in SourceCodester Loan Management System v1.0 Allowing Authenticated Attacker to Execute Arbitrary SQL |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Blind SQL Injection in SourceCodester Loan Management System v1.0 Allowing Authenticated Attacker to Execute Arbitrary SQL | |
| First Time appeared |
Sourcecodester
Sourcecodester loan Management System |
|
| Weaknesses | CWE-89 | |
| Vendors & Products |
Sourcecodester
Sourcecodester loan Management System |
|
| Metrics |
cvssV3_1
|
Tue, 31 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a POST request, allowing an authenticated attacker to inject malicious SQL commands. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-06T13:50:08.064Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30520
Updated: 2026-03-31T20:42:38.323Z
Status : Modified
Published: 2026-03-31T18:16:47.560
Modified: 2026-04-06T14:16:22.937
Link: CVE-2026-30520
No data.
OpenCVE Enrichment
Updated: 2026-04-07T08:08:20Z