CVE-2023-25196: Apache Fineract: SQL injection vulnerability
Published Mar 28, 2023
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to change or add data in certain components.
This issue affects Apache Fineract: from 1.4 through 1.8.2.
Affected Software
1 affected component
Apache Fineract>=1.4.0<=1.8.2
Event History
Mar 28, 2023
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-25196?
CVE-2023-25196 is an SQL Injection vulnerability found in Apache Fineract, an open-source financial services application.
2
What is the impact of CVE-2023-25196?
The vulnerability allows authorized users to manipulate or add data in certain components of Apache Fineract.
3
Which versions of Apache Fineract are affected by CVE-2023-25196?
CVE-2023-25196 affects Apache Fineract versions 1.4 through 1.8.2.
4
How severe is CVE-2023-25196?
CVE-2023-25196 has a severity rating of 4.3 (Medium).
5
How can I fix CVE-2023-25196?
To fix CVE-2023-25196, it is recommended to upgrade Apache Fineract to version 1.8.3 or later.