πŸ” CVE Alert

CVE-2026-4889

UNKNOWN 0.0

SQL Injection (SQLi) in eLoanApp Platform by RDL Technologies

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.

CWE CWE-89
Vendor rdl technologies
Product eloanapp platform
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for rdl technologies eloanapp platform

Be the first to know when new unknown vulnerabilities affecting rdl technologies eloanapp platform are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

RDL Technologies / eLoanApp Platform
0 < 06/10/2026

References

NVD β†— CVE.org β†— EPSS Data β†—
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-sqli-eloanapp-platform-rdl-technologies

Credits

Gonzalo Aguilar GarcΓ­a (6h4ack)