First published: Tue Jun 11 2019(Updated: )
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Fineract | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11801 is a SQL injection vulnerability in Apache Fineract before version 1.3.0.
CVE-2018-11801 has a severity rating of 9.8 (Critical).
CVE-2018-11801 allows attackers to execute arbitrary SQL commands on a m_center data related table in Apache Fineract.
To fix CVE-2018-11801, it is recommended to upgrade to Apache Fineract version 1.3.0 or later.
You can find more information about CVE-2018-11801 in the references provided: [1](http://www.openwall.com/lists/oss-security/2019/05/09/1) [2](http://www.securityfocus.com/bid/108291) [3](https://lists.apache.org/thread.html/32aa471180f8978b5f0ed64fcd862769f73c40bbe6cb948abdc899bf@%3Cdev.fineract.apache.org%3E)