ZeroHour

CVE-2018-20243

PoC
CVSS 3.1
7.5 high
EPSS
3%p85
Published
()
Modified
Description

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.

Vendors
apache
Products
fineract
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.