OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-4889

HIGH · CVSS 7.8 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The eLoanApp application is vulnerable to SQL injection through the 'logina' POST parameter in the user verification process, allowing attackers to execute boolean-based and time-based SQL injection attacks. Exploiting this vulnerability could lead to unauthorized access to sensitive database information and performance degradation due to delayed queries. Organizations using this application should prioritize patching this vulnerability to mitigate potential data breaches and service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-4889
Severity
HIGH
CVSS
7.8
EPSS
N/A

Original NVD Description

SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection. Successfully exploiting this vulnerability would allow an attacker to discover the platform's database engine and cause delays in database queries.