← Back

CVE-2018-20243

nvd nist
Published: Oct 13, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.

Affected (4)

Products: Apache: Fineract
1 product
Fineract
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.0.0 to 1.3.0
Version 0.4.0 incubating
Version 0.5.0 incubating
Version 0.6.0 incubating

References (2)

Timeline

No history available yet.