First published: Tue Mar 28 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to change or add data in certain components. This issue affects Apache Fineract: from 1.4 through 1.8.2.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Fineract | >=1.4.0<=1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25196 is an SQL Injection vulnerability found in Apache Fineract, an open-source financial services application.
The vulnerability allows authorized users to manipulate or add data in certain components of Apache Fineract.
CVE-2023-25196 affects Apache Fineract versions 1.4 through 1.8.2.
CVE-2023-25196 has a severity rating of 4.3 (Medium).
To fix CVE-2023-25196, it is recommended to upgrade Apache Fineract to version 1.8.3 or later.