CVE-2024-32838

Severity CVSS v4.0:
CRITICAL
Type:
CWE-89 SQL Injection
Publication date:
12/02/2025
Last modified:
12/02/2025

Description

SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker to inject malicious data into some of the REST API endpoints&amp;#39; query parameter. <br /> Users are recommended to upgrade to version 1.10.1, which fixes this issue.<br /> <br /> A SQL Validator has been implemented which allows us to configure a series of tests and checks against our SQL queries that will allow us to validate and protect against nearly all potential SQL injection attacks.