Impact
A SQL injection flaw has been identified in Apache Fineract's Report Execution API, specifically the runreports endpoint, that allows authenticated users possessing report‑run permissions to inject malicious SQL through crafted report parameters. Because the input values are incorporated directly into the generated SQL query without sufficient validation, a malicious user can execute arbitrary statements and access or modify data beyond the intended scope of the report.
Affected Systems
Apache Fineract, the open‑source cloud banking platform from the Apache Software Foundation, is affected in all releases up to and including 1.14.0.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, while an EPSS score of 2 % indicates a relatively low but non‑zero probability of exploitation. The issue is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authentication and appropriate report permissions, which are commonly granted to end users, making the attack vector realistic. A successful exploitation would grant an attacker elevated database access to read, modify, or delete data beyond the scope of the report.
OpenCVE Enrichment