← Back to browse · API

CVE-2022-44635

Severity
HIGH
CVSS
8.8
EPSS
0.68802
Risk score
59.28
CISA KEV
No
PoC
No
Published
2022-11-29
Modified
2025-04-25
First seen
2026-08-07
Aliases
EUVD-2022-47571, GHSA-MH5C-7Q6J-CWMG
Products
Apache Software Foundation:Apache Fineract Apache Fineract 1.7 ≤1.7.0, Apache Software Foundation:Apache Fineract Apache Fineract 1.8 ≤1.8.0
Sources
euvd EUVD-2022-47571

Description

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.

References