https://seclists.org/oss-sec/2025/q1/124: CVE-2024-32838: Apache Fineract: SQL injection vulnerabilities in offices API endpoint
Published Feb 12, 2025
·Updated
Affected Software
1 affected component
Apache Fineract>=1.4<1.10.1
Frequently Asked Questions
1
What is the severity of CVE-2024-32838?
The severity of CVE-2024-32838 is classified as important.
2
Which versions of Apache Fineract are affected by CVE-2024-32838?
Apache Fineract versions 1.4 through 1.9 are affected by CVE-2024-32838.
3
What type of vulnerability is CVE-2024-32838?
CVE-2024-32838 is an SQL injection vulnerability found in various API endpoints of Apache Fineract.
4
How do I fix CVE-2024-32838?
To fix CVE-2024-32838, users should update Apache Fineract to a version that is not affected by this vulnerability.
5
What can attackers do with CVE-2024-32838?
An authenticated attacker can exploit CVE-2024-32838 to inject malicious data into certain API endpoints.