Apache Fineract CVE-2018-1290 SQL Injection

Authors:Still in             Risk:High

CVE:CVE-2018-1290           0day:SQL Injection

0day -id:0DAY-176108         Date:2018-04-27

Summary

Apache Fineract is prone to an SQL-injection vulnerability because it fails to properly sanitize user-supplied input before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Vulnerable

Apache Fineract 1.0 
Apache Fineract 0.6.0-incubating
Apache Fineract 0.5.0-incubating
Apache Fineract 0.4.0-incubating

Leave a Reply