CVE-2018-1292

Publication date

2018-04-20 18:00:00

Family

apache

State

PUBLISHED

Description

Within the getReportType method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesnt have authorization for by way of the reportName parameter.