OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-4889 (CVSS 7.8)

NVD · officialPublished Oct 6, 2026Risk 23/100

SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.

CVSS
7.8
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source