216.73.216.57

CVE-2026-30523

· Published 01/04/2026 15:22 · Modified 01/04/2026 18:16

Labels: CVE-2026-30523 2026-04-01CVE-2026-30523CWE-20[email protected]

Essential information

Published
01/04/2026 15:22
Modified
01/04/2026 18:16
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CVSS metrics

Description

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive integer. An attacker can submit a negative value for the months parameter. The system accepts this invalid data and creates a loan plan with a negative duration.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sourcecodester / loan management system cpe:2.3:a:sourcecodester:loan_management_system:*:*:*:*:*:*:*:*

References