Vulnerabilities
Vulnerable Software
Apache:  >> Fineract  >> 0.3.1  Security Vulnerabilities
Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful.
CVSS Score
7.4
EPSS Score
0.034
Published
2021-05-27
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.
CVSS Score
9.8
EPSS Score
0.052
Published
2019-06-11
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.
CVSS Score
9.8
EPSS Score
0.052
Published
2019-06-11


Contact Us

Shodan ® - All rights reserved