Unrated severityNVD Advisory· Published Mar 29, 2024· Updated Feb 13, 2025
Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
CVE-2024-23538
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.
Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- cwiki.apache.org/confluence/display/FINERACT/Apache+Fineract+Security+Reportmitrevendor-advisory
- lists.apache.org/thread/by32w2dylzgbqm5940x3wj7519wolqxsmitrevendor-advisory
- www.openwall.com/lists/oss-security/2024/03/29/2mitre
News mentions
0No linked articles in our index yet.