CVE-2023-25197: apache fineract: SQL injection vulnerability in certain procedure calls
Published Mar 28, 2023
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to exploit this for limited impact on components.
This issue affects apache fineract: from 1.4 through 1.8.2.
Affected Software
1 affected component
Apache Fineract>=1.4.0<=1.8.2
Event History
Mar 28, 2023
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25197.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Improper Neutralization of Special Elements used in an SQL Command ( SQL Injection ) vulnerability in Apache Software Foundation apache fineract.'
3
What is the affected software?
The affected software is Apache Fineract versions 1.4 through 1.8.2.
4
What is the severity of CVE-2023-25197?
The severity of CVE-2023-25197 is medium with a CVSS score of 6.3.
5
How can I fix CVE-2023-25197?
To fix CVE-2023-25197, update Apache Fineract to a version higher than 1.8.2.