Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to change or add data in certain components. This issue affects Apache Fineract: from 1.4 through 1.8.2.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/m9x3vpn3bry4fympkzxnnz4qx0oc0w8m | Mailing List Vendor Advisory |
Configurations
History
31 Mar 2023, 13:42
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://lists.apache.org/thread/m9x3vpn3bry4fympkzxnnz4qx0oc0w8m - Mailing List, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CPE | cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:* |
28 Mar 2023, 16:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-28 12:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-25196
Mitre link : CVE-2023-25196
CVE.ORG link : CVE-2023-25196
JSON object : View
Products Affected
apache
- fineract
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')