PT-2018-11467 · Apache · Apache Fineract

Publicado

2018-04-20

·

Atualizado

2018-05-22

·

CVE-2018-1291

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Fineract versions 0.4.0-incubating through 1.0.0
Description The issue allows a hacker to inject SQL statements through the orderBy query parameter, which is appended directly to SQL statements. This can enable unauthorized access to read or update data. The orderBy parameter is exposed through various REST endpoints used to query domain-specific entities.
Recommendations For Apache Fineract versions 0.4.0-incubating through 1.0.0, as a temporary workaround, consider restricting access to the orderBy query parameter in the affected REST endpoints until a patch is available. Additionally, restrict the use of the order parameter to prevent SQL injection.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1291

Produtos afetados

Apache Fineract