Description
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL injection allowing data tampering or disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the admin index functionality of CodeAstro Simple Loan Management System 1.0. Manipulating the ‘g_name’ argument permits a classic SQL injection, which may let an attacker execute arbitrary SQL against the underlying database. The flaw is a classic injection weakness (CWE‑74 and CWE‑89) and can be exploited from any remote location, with an exploit already released publicly. If successfully leveraged, the attacker can read, modify, or delete sensitive data stored in the application’s database.

Affected Systems

The affected product is CodeAstro Simple Loan Management System version 1.0. The vulnerability is triggered via the file /admin/index.php when the g_name query string parameter is supplied without proper validation.

Risk and Exploitability

The CVSS score of 5.3 classifies the issue as medium severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector is remote and the exploit is publicly available, an attacker with network access to the application can exploit it. Successful exploitation requires only the ability to send crafted requests to /admin/index.php, and there are no additional complex prerequisites noted in the description.

Generated by OpenCVE AI on October 2, 2026 at 15:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and apply any vendor-released patch or newer version of CodeAstro Simple Loan Management System that addresses the g_name injection flaw.
  • Restrict access to /admin/index.php so that only trusted and authenticated users can reach the vulnerable endpoint.
  • Implement defensive coding such as input validation for g_name and use of parameterized SQL queries or prepared statements to eliminate injection vectors.

Generated by OpenCVE AI on October 2, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Title CodeAstro Simple Loan Management System index.php sql injection
First Time appeared Codeastro
Codeastro simple Loan Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:codeastro:simple_loan_management_system:*:*:*:*:*:*:*:*
Vendors & Products Codeastro
Codeastro simple Loan Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Codeastro Simple Loan Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T14:30:10.567Z

Reserved: 2026-10-02T04:19:57.031Z

Link: CVE-2026-104625

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T15:17:08.660

Modified: 2026-10-02T17:52:32.600

Link: CVE-2026-104625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T16:00:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')