CVE-2018-11801

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICAL
EPSS
3.3%
top 12.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 24

Description

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/fineract< 1.3.0
CVEListV5apache/apache_fineractApache Fineract versions before 1.3.0 are affected

🔴Vulnerability Details

2
GHSA
GHSA-p9jr-5339-4hvx: SQL injection vulnerability in Apache Fineract before 12022-05-24
CVEList
CVE-2018-11801: SQL injection vulnerability in Apache Fineract before 12019-06-11
CVE-2018-11801 (CRITICAL CVSS 9.8) | SQL injection vulnerability in Apac | cvebase.io