Vulnerabilities > Apache > Fineract > 1.3.0

DATE CVE VULNERABILITY TITLE RISK
2022-11-29 CVE-2022-44635 Path Traversal vulnerability in Apache Fineract
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code.
network
low complexity
apache CWE-22
8.8
2021-05-27 CVE-2020-17514 Unspecified vulnerability in Apache Fineract
Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method.
network
high complexity
apache
7.4
2020-10-13 CVE-2018-20243 Insufficiently Protected Credentials vulnerability in Apache Fineract
The implementation of POST with the username and password in the URL parameters exposed the credentials.
network
low complexity
apache CWE-522
5.0