Description

SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints' query parameter.  Users are recommended to upgrade to version 1.10.1, which fixes this issue. A SQL Validator has been implemented which allows us to configure a series of tests and checks against our SQL queries that will allow us to validate and protect against nearly all potential SQL injection attacks.

INFO

Published Date :

2025-02-12T09:44:15.943Z

Last Modified :

2025-02-12T18:03:27.737Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2024-32838 vulnerability.

Vendors Products
Apache
  • Fineract
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-32838.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability