vendor:
Akaunting
by:
u32i
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
94
CWE
Product Name: Akaunting
Affected Version From: 3.1.2003
Affected Version To: 3.1.2003
Patch Exists: YES
Related CWE: CVE-2024-22836
CPE: a:akaunting:akaunting:3.1.3
Platforms Tested: Ubuntu 22.04
2024
Akaunting <= 3.1.3 Remote Code Execution
Akaunting version 3.1.3 and below are vulnerable to Remote Code Execution (RCE) allowing an attacker to execute arbitrary commands on the target system. By injecting malicious commands through a crafted request to the 'companies' endpoint, an attacker can exploit this vulnerability. CVE-2024-22836 has been assigned to this issue.
Mitigation:
Update Akaunting to version 3.1.4 or later to prevent this Remote Code Execution vulnerability.