Description
SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.
Published: 2026-10-06
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a classic SQL injection in the eLoanApp application. An attacker can send specially crafted POST data to the ‘logina’ parameter on the /ajax/users.php?op=verify endpoint. The flaw allows both boolean‑based and time‑based SQL injection, giving the attacker the ability to identify the database engine in use and to inject statements that delay the execution of queries. This can lead to information disclosure and a denial‑of‑service effect if the attacker chooses to exploit the delay.

Affected Systems

The flaw affects the eLoanApp Platform developed by RDL Technologies. No specific affected version is listed in the CNA data, so any deployable instance of the platform is potentially vulnerable until a vendor patch is released.

Risk and Exploitability

The vendor’s CVSS score of 7.8 rating the flaw as high and the lack of an EPSS score or KEV listing indicate it is a serious issue, but the likelihood of exploitation is unclear. Based on the description, the likely attack vector is an unauthenticated HTTP POST request to the publicly exposed /ajax/users.php?op=verify endpoint that leverages the vulnerable ‘logina’ parameter to perform boolean or time‑based injection.

Generated by OpenCVE AI on October 6, 2026 at 09:21 UTC.

Remediation

Vendor Solution

No solution has been reported yet.


OpenCVE Recommended Actions

  • Deploy a Web Application Firewall to block common SQL injection payload patterns against the /ajax/users.php?op=verify endpoint.
  • Modify the application code to use parameterized queries or prepared statements for the ‘logina’ parameter, ensuring user input is not concatenated into SQL statements.
  • Restrict external access to the endpoint, limiting it to trusted IP ranges or internal network segments until a vendor patch becomes available.
  • Conduct a focused code review and penetration test on input handling to identify and remediate similar injection points.

Generated by OpenCVE AI on October 6, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.
Title SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies
First Time appeared Rdl Technologies
Rdl Technologies eloanapp Platform
Weaknesses CWE-89
CPEs cpe:2.3:a:rdl_technologies:eloanapp_platform:*:*:*:*:*:*:*:*
Vendors & Products Rdl Technologies
Rdl Technologies eloanapp Platform
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L'}


Subscriptions

Rdl Technologies Eloanapp Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-06T08:19:49.785Z

Reserved: 2026-03-26T12:50:11.948Z

Link: CVE-2026-4889

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:56.317

Modified: 2026-10-06T09:17:56.317

Link: CVE-2026-4889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T09:30:13Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')