https://seclists.org/oss-sec/2024/q1/266: CVE-2024-23538: Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Published Mar 29, 2024
·Updated
Affected Software
1 affected component
Apache Fineract
Frequently Asked Questions
1
What is the severity of CVE-2024-23538?
The severity of CVE-2024-23538 has been rated as critical due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-23538?
To fix CVE-2024-23538, ensure you update Apache Fineract to the latest patched version that resolves the SQL injection vulnerability.
3
What systems are affected by CVE-2024-23538?
CVE-2024-23538 affects Apache Fineract under certain configurations that allow the sqlSearch parameter to be exploited.
4
What type of vulnerability is CVE-2024-23538?
CVE-2024-23538 is classified as an SQL injection vulnerability, which allows malicious actors to manipulate database queries.
5
When was CVE-2024-23538 published?
CVE-2024-23538 was published on March 29, 2024.