Junglewise Threat Intelligence

CVE-2025-69948: SourceCodester Modern Loan Management System SQL injection in delete_group.php

CVE-2025-69948 · Severity: info · CVSS 7.5 · Published 2026-07-31

Executive brief

The SourceCodester Modern Loan Management System, a software used for managing financial loans and borrower groups, contains a security flaw in its administrative interface. An attacker can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive financial records, borrower information, and system configuration data.

Technical details

A SQL injection vulnerability exists in SourceCodester Modern Loan Management System 1.0 within the '/admin/delete_group.php' script. The application fails to properly sanitize the 'id' GET parameter before using it in a database query. A remote attacker can exploit this by sending a specially crafted URL containing SQL commands. Successful exploitation allows the attacker to bypass authentication or extract sensitive information from the database. Based on the endpoint location, this likely affects administrative functions related to group management.

Affected products

  • SourceCodester Modern Loan Management System 1.0

Timeline

  • 2026-07-31: disclosed: CVE published to NVD dataset

References

Related threats