SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.

Project Subscriptions

Vendors Products
Rdl Technologies Subscribe
Eloanapp Platform Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution has been reported yet.


Workaround

No workaround given by the vendor.

History

Tue, 06 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.
Title SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies
First Time appeared Rdl Technologies
Rdl Technologies eloanapp Platform
Weaknesses CWE-89
CPEs cpe:2.3:a:rdl_technologies:eloanapp_platform:*:*:*:*:*:*:*:*
Vendors & Products Rdl Technologies
Rdl Technologies eloanapp Platform
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-06T08:19:49.785Z

Reserved: 2026-03-26T12:50:11.948Z

Link: CVE-2026-4889

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses