cvedb.io
CVE-2018-1292
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2018-04-20T18:29:00.707 · Last modified 2026-06-17T01:50:56.260

Summary

Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'reportName' parameter.

Affected products

apache — fineract

Does this affect you?

Add your gear to cvedb and we'll alert you only when apache ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.