Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.
[
{
"vendor": "Apache Software Foundation",
"product": "Apache Fineract",
"versions": [
{
"version": "Apache Fineract 1.8",
"status": "affected",
"lessThanOrEqual": "1.8.0",
"versionType": "custom"
},
{
"version": "Apache Fineract 1.7",
"status": "affected",
"lessThanOrEqual": "1.7.0",
"versionType": "custom"
}
]
}
]