Description

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive integer. An attacker can submit a negative value for the months parameter. The system accepts this invalid data and creates a loan plan with a negative duration.

INFO

Published Date :

2026-04-01T00:00:00.000Z

Last Modified :

2026-04-01T17:56:53.409Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2026-30523 vulnerability.

Vendors Products
Sourcecodester
  • Loan Management System
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-30523.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact