akaunting.com
https://akaunting.com/ CVE-2024-22836
CRITICAL
Akaunting < 3.1.3 - RCE
Record summary
CVE-2024-22836 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 8, 2024 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBAkaunting < 3.1.3 - RCEExploitDB exploitby u32iNot analyzed1 file
References
4github.com
https://github.com/akaunting/akaunting/releases/tag/3.1.4 github.com
https://github.com/u32i/cve/tree/main/CVE-2024-22836 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-22836