CVE-2018-20243: Apache Fineract
High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.
The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
Affected products
- Apache Fineract: from 1.0.0, up to and including 1.3.0; version 0.4.0 only; version 0.5.0 only; version 0.6.0 only
Published 2020-10-13. Last modified 2026-06-17.