High severity7.5NVD Advisory· Published Oct 13, 2020· Updated Jun 17, 2026
CVE-2018-20243
CVE-2018-20243
Description
The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
Affected products
6cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:*range: >=1.0.0,<=1.3.0
- cpe:2.3:a:apache:fineract:0.4.0:incubating:*:*:*:*:*:*
- cpe:2.3:a:apache:fineract:0.5.0:incubating:*:*:*:*:*:*
- cpe:2.3:a:apache:fineract:0.6.0:incubating:*:*:*:*:*:*
- (no CPE)
- Apache/fineractdescription
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread.html/r040d46835aff3c192656b549ca82f62d87fb044ef9a9dd49408b49b4%40%3Cdev.fineract.apache.org%3EnvdExploitMailing ListPatchThird Party Advisory
News mentions
0No linked articles in our index yet.