CVE-2021-36801

HIGH

Akaunting < 2.1.12 - IDOR

Title source: rule
STIX 2.1

Description

Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0029
EPSS Percentile 51.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-639
Status published
Products (1)
akaunting/akaunting < 2.1.12
Published Aug 04, 2021
Tracked Since Feb 18, 2026