logo

Apache Fineract SQL Injection Vulnerability Allows Malicious Data Injection

ID: 90d60913-2f14-5ac3-9697-63c97eb61953

STIX ID: report--90d60913-2f14-5ac3-9697-63c97eb61953

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-02-14

Date Updated: 2026-04-22

Author: Divya

...
...

The Apache Software Foundation disclosed a critical SQL injection vulnerability (CVE-2024-32838) in Apache Fineract versions 1.4–1.9 stemming from weak input validation in several REST API endpoints, which could allow authenticated attackers to inject SQL and compromise financial data; Apache released Fineract 1.10.1 with a SQL Validator fix and advises immediate upgrades, log reviews, and additional application-layer protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.