Impact
The vulnerability is a classic SQL injection in the eLoanApp application. An attacker can send specially crafted POST data to the ‘logina’ parameter on the /ajax/users.php?op=verify endpoint. The flaw allows both boolean‑based and time‑based SQL injection, giving the attacker the ability to identify the database engine in use and to inject statements that delay the execution of queries. This can lead to information disclosure and a denial‑of‑service effect if the attacker chooses to exploit the delay.
Affected Systems
The flaw affects the eLoanApp Platform developed by RDL Technologies. No specific affected version is listed in the CNA data, so any deployable instance of the platform is potentially vulnerable until a vendor patch is released.
Risk and Exploitability
The vendor’s CVSS score of 7.8 rating the flaw as high and the lack of an EPSS score or KEV listing indicate it is a serious issue, but the likelihood of exploitation is unclear. Based on the description, the likely attack vector is an unauthenticated HTTP POST request to the publicly exposed /ajax/users.php?op=verify endpoint that leverages the vulnerable ‘logina’ parameter to perform boolean or time‑based injection.
OpenCVE Enrichment