CVE-2021-36800

HIGH

Akaunting < 2.1.13 - Remote Code Execution via Invoice Price Parameter

Title source: llm
STIX 2.1

Description

Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed directly. This issue was fixed in version 2.1.13 of the product.

References (1)

Core 1
Core References

Scores

CVSS v3 8.7
EPSS 0.0150
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-94
Status published
Products (1)
akaunting/akaunting < 2.1.13
Published Aug 04, 2021
Tracked Since Feb 18, 2026