Apache

Fineract

17 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.32%
  • Published 11.06.2019 17:29:00
  • Last modified 21.11.2024 03:44:03

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.

  • EPSS 3.32%
  • Published 11.06.2019 17:29:00
  • Last modified 21.11.2024 03:44:03

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

  • EPSS 0.6%
  • Published 20.04.2018 18:29:00
  • Last modified 21.11.2024 03:59:33

Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'reportName' parameter.

  • EPSS 0.27%
  • Published 20.04.2018 18:29:00
  • Last modified 21.11.2024 03:59:33

Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' which are appended directly with SQL statements. A hacker/user can inject...

  • EPSS 0.62%
  • Published 20.04.2018 18:29:00
  • Last modified 21.11.2024 03:59:33

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like retrieveAuditEntries of AuditsAp...

  • EPSS 0.56%
  • Published 20.04.2018 18:29:00
  • Last modified 21.11.2024 03:59:33

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with ...

  • EPSS 0.19%
  • Published 14.12.2017 15:29:00
  • Last modified 20.04.2025 01:37:25

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endp...