Apache

Fineract

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.42%
  • Veröffentlicht 20.04.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:33

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like retrieveAuditEntries of AuditsAp...

  • EPSS 2.67%
  • Veröffentlicht 20.04.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:33

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with ...

  • EPSS 2.09%
  • Veröffentlicht 14.12.2017 15:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endp...