NA

CVE-2024-22836

Published: 08/02/2024 Updated: 15/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An OS command injection vulnerability exists in Akaunting v3.1.3 and previous versions. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

Vulnerable Product Search on Vulmon Subscribe to Product

akaunting akaunting

Vendor Advisories

Check Point Reference: CPAI-2024-0164 Date Published: 7 Apr 2024 Severity: Critical ...

Exploits

Akaunting versions 313 and below suffer from a remote command execution vulnerability ...