Apache Fineract SQL Injection Vulnerability Allows Malicious Data Injection
ID: 90d60913-2f14-5ac3-9697-63c97eb61953
STIX ID: report--90d60913-2f14-5ac3-9697-63c97eb61953
Feed Name: GBHackers
Threat Score
The Apache Software Foundation disclosed a critical SQL injection vulnerability (CVE-2024-32838) in Apache Fineract versions 1.4–1.9 stemming from weak input validation in several REST API endpoints, which could allow authenticated attackers to inject SQL and compromise financial data; Apache released Fineract 1.10.1 with a SQL Validator fix and advises immediate upgrades, log reviews, and additional application-layer protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
