https://seclists.org/oss-sec/2024/q1/267: CVE-2024-23539: Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Published Mar 29, 2024
·Updated
Affected Software
1 affected component
Apache Fineract
Frequently Asked Questions
1
What is the severity of CVE-2024-23539?
CVE-2024-23539 has been rated as a medium severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2024-23539?
To fix CVE-2024-23539, update Apache Fineract to the latest version where the vulnerability has been patched.
3
What is the impact of CVE-2024-23539?
The impact of CVE-2024-23539 allows attackers to manipulate SQL queries, which could lead to unauthorized access to sensitive data.
4
Which endpoints are affected by CVE-2024-23539?
CVE-2024-23539 affects specific endpoints that utilize the sqlSearch parameter under certain system configurations.
5
When was CVE-2024-23539 published?
CVE-2024-23539 was published on March 29, 2024.