VulnerabilityModified
CVE-2024-22836
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier.
CRITICAL 9.8EPSS 30.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 30.04% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- akaunting/akaunting
- Source
- cve@mitre.org
References
- https://akaunting.com/Product
- https://github.com/akaunting/akaunting/releases/tag/3.1.4Release Notes
- https://github.com/u32i/cve/tree/main/CVE-2024-22836Third Party Advisory
- https://akaunting.com/Product
- https://github.com/akaunting/akaunting/releases/tag/3.1.4Release Notes
- https://github.com/u32i/cve/tree/main/CVE-2024-22836Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.