|
Message-ID: <919ca824-7bfc-76a6-3d94-88b2c5bfea62@apache.org> Date: Mon, 27 Mar 2023 16:21:18 +0000 From: James Dailey <jdailey@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2023-25197: apache fineract: SQL injection vulnerability in certain procedure calls Severity: moderate Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to exploit this for limited impact on components. This issue affects apache fineract: from 1.4 through 1.8.2. Credit: Eugene Lim at Cyber Security Group (CSG) Government Technology Agency GOVTECH.sg (reporter) aleks@...che.org (remediation developer) References: https://fineract.apache.org/ https://www.cve.org/CVERecord?id=CVE-2023-25197
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.