CVE-2018-1292: SQL Injection
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'reportName' parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-1292.
What is the severity of CVE-2018-1292?
The severity of CVE-2018-1292 is high with a CVSS score of 8.1.
Which software versions are affected by CVE-2018-1292?
Apache Fineract versions 0.4.0, 0.5.0, 0.6.0, and 1.0.0 are affected by CVE-2018-1292.
How can a hacker exploit CVE-2018-1292?
A hacker can exploit CVE-2018-1292 by injecting SQL through the 'reportName' parameter in the 'getReportType' method, allowing unauthorized reading or updating of data.
Are there any references for more information about CVE-2018-1292?
Yes, you can find more information about CVE-2018-1292 at the following references: [link1](http://www.securityfocus.com/bid/104007), [link2](https://lists.apache.org/thread.html/a24610817845d022d5fe89cfe21563ef83bea35ca95de867cd2c4ee9@%3Cdev.fineract.apache.org%3E).