Vulnerabilities
Vulnerable Software
Apache:  >> Fineract  >> 1.4.0  Security Vulnerabilities
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.
CVSS Score
8.8
EPSS Score
0.41
Published
2022-11-29
Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could be successful.
CVSS Score
7.4
EPSS Score
0.008
Published
2021-05-27


Contact Us

Shodan ® - All rights reserved