Business Logic Flaw in SourceCodester Loan Management System
CVE-2026-30522
6.5MEDIUM
What is CVE-2026-30522?
A business logic flaw has been identified in the SourceCodester Loan Management System v1.0 stemming from improper server-side validation. While the application restricts users from entering negative values in the 'Monthly Overdue Penalty' field on the frontend, this restriction does not extend to the backend. As a result, an authenticated attacker can exploit this vulnerability by manipulating HTTP POST requests to input negative values for penalty rates, potentially leading to unintended financial consequences.
