CVE-2024-23539: Apache Fineract

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

Affected products

  • Apache Fineract: before 1.9.0 (fixed in 1.9.0)

Published 2024-03-29. Last modified 2026-06-17.