CVE-2026-4889 PUBLISHED

SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies

Assigner: INCIBE
Reserved: 26.03.2026 Published: 06.10.2026 Updated: 06.10.2026

SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:L/SA:L
CVSS Score: 7.8

Product Status

Vendor RDL Technologies
Product eLoanApp Platform
Versions Default: unaffected
  • affected from 0 to 06/10/2026 (excl.)

Solutions

No solution has been reported yet.

Credits

  • Gonzalo Aguilar García (6h4ack) finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE