CVE-2023-25196: Apache Fineract

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to change or add data in certain components.   This issue affects Apache Fineract: from 1.4 through 1.8.2.

Affected products

  • Apache Fineract: from 1.4.0, up to and including 1.8.2

Published 2023-03-28. Last modified 2026-06-17.