CVE-2023-25196

Source
https://cve.org/CVERecord?id=CVE-2023-25196
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25196.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-25196
Published
2023-03-28T11:16:57.603Z
Modified
2026-07-15T01:49:07.984769720Z
Summary
Apache Fineract: SQL injection vulnerability
Details

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to change or add data in certain components.  

This issue affects Apache Fineract: from 1.4 through 1.8.2.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25196.json",
    "cna_assigner": "apache",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.4"
                },
                {
                    "last_affected": "1.8.2"
                }
            ]
        },
        {
            "extracted_events": [
                {
                    "introduced": "1.4"
                },
                {
                    "fixed": "1.8.2"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/apache/fineract

Affected ranges

Type
GIT
Repo
https://github.com/apache/fineract
Events
Database specific
{
    "cpe": "cpe:2.3:a:apache:fineract:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "1.4.0"
        },
        {
            "last_affected": "1.8.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25196.json"