Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <eed59b0c-fd99-1a0f-00df-dfbc8c120ec5@apache.org>
Date: Mon, 27 Mar 2023 16:21:03 +0000
From: James Dailey <jdailey@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2023-25196: Apache Fineract: SQL injection vulnerability  

Severity: important

Description:

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract.
Authorized users may be able to change or add data in certain components.  

This issue affects Apache Fineract: from 1.4 through 1.8.2.

Credit:

 Zhang Baocheng at Leng Jing Qi Cai Security Lab (reporter)
Aleks@...che.org (remediation developer)

References:

https://fineract.apache.org/
https://www.cve.org/CVERecord?id=CVE-2023-25196

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.