Impact
The Modern Loan Management System version 1.0 contains a vulnerability that allows an attacker to inject arbitrary SQL code into the "id" parameter of the "/admin/delete_group.php" endpoint. This flaw enables the execution of unintended SQL statements. The weakness corresponds to the well‑known SQL Injection weakness, categorized as CWE‑89.
Affected Systems
The vulnerability is present in SourceCodester’s Modern Loan Management System 1.0. The flaw is exposed through the administrative delete_group.php page, particularly the "id" query parameter. No other product variants or versions are specified, and no vendor‑specific patch information is available.
Risk and Exploitability
The vulnerability can be triggered by providing a crafted id value to the /admin/delete_group.php endpoint. The EPSS score is <1%, indicating a very low probability of exploitation. This CVE is not listed in CISA's KEV catalog. The CVSS score is 9.8, indicating critical severity.
OpenCVE Enrichment