A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

cve CVE-2026-104625 2 sources, 2 claims · Watch

NVD writes:
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectscodeastro/simple_loan_management_system
NVD says “CodeAstro · Simple Loan Management System”
made_bycodeastro
NVD says “CodeAstro”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
GitHub advisories6.3
receipt
Source
GitHub advisories
Its words
6.3
Read by
field:cvss.score
Said since
2026-10-02 18:00 UTC
Last answered
2026-10-02 18:02 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104625",
  "cvss": {
    "score": 6.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 2.1,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-74",
      "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
    }
  ],
  "description": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.",
  "ghsa_id": "GHSA-6v8g-5jx8-5p7w",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-6v8g-5jx8-5p7w",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-6v8g-5jx8-5p7w"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104625"
    }
  ],
  "nvd_published_at": "2026-10-02T15:17:08Z",
  "published_at": "2026-10-02T15:31:26Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104625",
    "https://github.com/yihaofuweng/cve/issues/77",
    "https://codeastro.com",
    "https://vuldb.com/cve/CVE-2026-104625",
    "https://vuldb.com/submit/963586",
    "https://vuldb.com/vuln/412924",
    "https://vuldb.com/vuln/412924/cti",
    "https://github.com/advisories/GHSA-6v8g-5jx8-5p7w"
  ],
  "repository_advisory_url": null,
  "severity": "low",
  "source_code_location": "",
  "summary": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T15:31:37Z",
  "url": "https://api.github.com/advisories/GHSA-6v8g-5jx8-5p7w",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cvss
cvss
NVD6.3
receipt
Source
NVD
Its words
6.3
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:codeastro:simple_loan_management_system:*:*:*:*:*:*:*:*"
            ],
            "product": "Simple Loan Management System",
            "vendor": "CodeAstro",
            "versions": [
              {
                "status": "affected",
                "version": "1.0"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks."
      }
    ],
    "id": "CVE-2026-104625",
    "lastModified": "2026-10-02T17:52:32.600",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 6.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 8.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.1,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T15:17:08.660",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://codeastro.com/"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/yihaofuweng/cve/issues/77"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/cve/CVE-2026-104625"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/submit/963586"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924/cti"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-89"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Primary"
      }
    ]
  }
}
—
Cwe
cwe
GitHub advisoriesCWE-74
receipt
Source
GitHub advisories
Its words
CWE-74
Read by
field:cwes[].cwe_id
Said since
2026-10-02 18:00 UTC
Last answered
2026-10-02 18:02 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104625",
  "cvss": {
    "score": 6.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 2.1,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-74",
      "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
    }
  ],
  "description": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.",
  "ghsa_id": "GHSA-6v8g-5jx8-5p7w",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-6v8g-5jx8-5p7w",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-6v8g-5jx8-5p7w"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104625"
    }
  ],
  "nvd_published_at": "2026-10-02T15:17:08Z",
  "published_at": "2026-10-02T15:31:26Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104625",
    "https://github.com/yihaofuweng/cve/issues/77",
    "https://codeastro.com",
    "https://vuldb.com/cve/CVE-2026-104625",
    "https://vuldb.com/submit/963586",
    "https://vuldb.com/vuln/412924",
    "https://vuldb.com/vuln/412924/cti",
    "https://github.com/advisories/GHSA-6v8g-5jx8-5p7w"
  ],
  "repository_advisory_url": null,
  "severity": "low",
  "source_code_location": "",
  "summary": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T15:31:37Z",
  "url": "https://api.github.com/advisories/GHSA-6v8g-5jx8-5p7w",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Product
product
NVDSimple Loan Management System
receipt
Source
NVD
Its words
Simple Loan Management System
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:codeastro:simple_loan_management_system:*:*:*:*:*:*:*:*"
            ],
            "product": "Simple Loan Management System",
            "vendor": "CodeAstro",
            "versions": [
              {
                "status": "affected",
                "version": "1.0"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks."
      }
    ],
    "id": "CVE-2026-104625",
    "lastModified": "2026-10-02T17:52:32.600",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 6.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 8.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.1,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T15:17:08.660",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://codeastro.com/"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/yihaofuweng/cve/issues/77"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/cve/CVE-2026-104625"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/submit/963586"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924/cti"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-89"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
GitHub advisorieslow
Below 4.0.
receipt
Source
GitHub advisories
Its words
low
Read by
field:severity
Said since
2026-10-02 18:00 UTC
Last answered
2026-10-02 18:02 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104625",
  "cvss": {
    "score": 6.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 6.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 2.1,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-74",
      "name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
    }
  ],
  "description": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.",
  "ghsa_id": "GHSA-6v8g-5jx8-5p7w",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-6v8g-5jx8-5p7w",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-6v8g-5jx8-5p7w"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104625"
    }
  ],
  "nvd_published_at": "2026-10-02T15:17:08Z",
  "published_at": "2026-10-02T15:31:26Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104625",
    "https://github.com/yihaofuweng/cve/issues/77",
    "https://codeastro.com",
    "https://vuldb.com/cve/CVE-2026-104625",
    "https://vuldb.com/submit/963586",
    "https://vuldb.com/vuln/412924",
    "https://vuldb.com/vuln/412924/cti",
    "https://github.com/advisories/GHSA-6v8g-5jx8-5p7w"
  ],
  "repository_advisory_url": null,
  "severity": "low",
  "source_code_location": "",
  "summary": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is...",
  "type": "unreviewed",
  "updated_at": "2026-10-02T15:31:37Z",
  "url": "https://api.github.com/advisories/GHSA-6v8g-5jx8-5p7w",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Status
status
NVDDeferred
receipt
Source
NVD
Its words
Deferred
Read by
field:cve.vulnStatus
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:codeastro:simple_loan_management_system:*:*:*:*:*:*:*:*"
            ],
            "product": "Simple Loan Management System",
            "vendor": "CodeAstro",
            "versions": [
              {
                "status": "affected",
                "version": "1.0"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks."
      }
    ],
    "id": "CVE-2026-104625",
    "lastModified": "2026-10-02T17:52:32.600",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 6.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 8.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.1,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T15:17:08.660",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://codeastro.com/"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/yihaofuweng/cve/issues/77"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/cve/CVE-2026-104625"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/submit/963586"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924/cti"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-89"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDCodeAstro
receipt
Source
NVD
Its words
CodeAstro
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-02 18:04 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:codeastro:simple_loan_management_system:*:*:*:*:*:*:*:*"
            ],
            "product": "Simple Loan Management System",
            "vendor": "CodeAstro",
            "versions": [
              {
                "status": "affected",
                "version": "1.0"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks."
      }
    ],
    "id": "CVE-2026-104625",
    "lastModified": "2026-10-02T17:52:32.600",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 6.5,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 8.0,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 2.1,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T15:17:08.660",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://codeastro.com/"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/yihaofuweng/cve/issues/77"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/cve/CVE-2026-104625"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/submit/963586"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/vuln/412924/cti"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-89"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Primary"
      }
    ]
  }
}
—

vulnerability

A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
zetlyn/cve-nvd · 2026-10-02
cvss 6.3 product Simple Loan Management System status Deferred vendor CodeAstro source
A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is...
zetlyn/cve-ghsa · 2026-10-02
cvss 6.3 cwe CWE-74 severity low source