CVE-2024-23538: Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Published Mar 29, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5.
Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.
Affected Software
1 affected component
Apache Fineract<1.9.0
Event History
Mar 29, 2024
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23538?
CVE-2024-23538 is classified as a high severity vulnerability due to the potential for SQL Injection attacks.
2
How do I fix CVE-2024-23538?
To fix CVE-2024-23538, upgrade Apache Fineract to version 1.8.5 or 1.9.0.
3
Which versions of Apache Fineract are affected by CVE-2024-23538?
Apache Fineract versions prior to 1.8.5 are affected by CVE-2024-23538.
4
What kind of vulnerability is CVE-2024-23538?
CVE-2024-23538 is an SQL Injection vulnerability caused by improper neutralization of special elements used in SQL commands.
5
Can CVE-2024-23538 lead to unauthorized access to data?
Yes, CVE-2024-23538 can potentially allow attackers to gain unauthorized access to sensitive data in the database.