Vulnerability Description
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like retrieveAuditEntries of AuditsApiResource Class and retrieveCommands of MakercheckersApiResource Class.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Fineract | 0.4.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103975Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/69cc2b54b32f0936f40dc9be41f41fe1566710a75ed
- http://www.securityfocus.com/bid/103975Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/69cc2b54b32f0936f40dc9be41f41fe1566710a75ed
FAQ
What is CVE-2018-1290?
CVE-2018-1290 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be don...
How severe is CVE-2018-1290?
CVE-2018-1290 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-1290?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Fineract.