Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-16106
HistoryApr 02, 2024 - 12:00 a.m.

Apache Fineract SQL Injection Vulnerability (CNVD-2024-16106)

2024-04-0200:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
apache fineract
open source digital financial services
sql injection
vulnerability
apache foundation
data management
loan and savings
real-time financial data
attacker
back-end database
sql statements
sqlsearch parameter
cnvd

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

Apache Fineract is a set of open source digital financial services platform of the U.S. Apache (Apache) Foundation. The platform can provide users with data management, loan and savings portfolio management and real-time financial data and other functions. Apache Fineract versions prior to 1.8.5 suffer from a SQL injection vulnerability that can be exploited by an attacker to view, add, modify, or delete information in the back-end database by sending specially crafted SQL statements using the sqlSearch parameter.

CPENameOperatorVersion
apache fineractlt1.8.5

7.4 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

Related for CNVD-2024-16106