Unrated severityNVD Advisory· Published Mar 29, 2024· Updated Feb 13, 2025
Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
CVE-2024-23539
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.
Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- cwiki.apache.org/confluence/display/FINERACT/Apache+Fineract+Security+Reportmitrevendor-advisory
- lists.apache.org/thread/g8sv1gnjv716lx2h89jbvjdgtrrjmy7hmitrevendor-advisory
- www.openwall.com/lists/oss-security/2024/03/29/3mitre
News mentions
0No linked articles in our index yet.