Apache fineract是美国Apache基金会开源的一套金融科技平台。 Apache Fineract 1.14.0及之前版本存在SQL注入漏洞,该漏洞源于对orderBy请求参数验证不充分,导致容易受到SQL注入攻击,可能导致基于时间的盲SQL注入进行数据渗漏,并可能耗尽数据库连接池导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Fineract | ≤ 1.14.0 |
affected |
1.15.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Fineract | 0 ~ 1.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56287 | Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to | |
| CVE-2026-35152 | Apache Fineract: SQL injection in runreports endpoint | |
| CVE-2026-26032 | Apache Ivy: PackagerResolver path traversal vulnerability |
No comments yet