A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive integer. An attacker can submit a negative value for the months parameter. The system accepts this invalid data and creates a loan plan with a negative duration.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Negative Duration Loan Plan Allowance | |
| First Time appeared |
Sourcecodester
Sourcecodester loan Management System |
|
| Vendors & Products |
Sourcecodester
Sourcecodester loan Management System |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive integer. An attacker can submit a negative value for the months parameter. The system accepts this invalid data and creates a loan plan with a negative duration. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-01T00:00:00.000Z
Updated: 2026-04-01T17:56:53.409Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30523
Updated: 2026-04-01T17:56:23.867Z
Status : Awaiting Analysis
Published: 2026-04-01T15:22:59.170
Modified: 2026-04-03T16:11:11.357
Link: CVE-2026-30523
No data.