CVE-2026-40522

HIGH

FrontAccounting < 2.4.20 SQL Injection via rep601.php

Title source: cna
STIX 2.1

Description

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL syntax through the unparameterized WHERE clause to retrieve sensitive information including usernames, password hashes, and email addresses from the users table, rendered into PDF report output.

Scores

CVSS v3 7.1
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89 CWE-916
Status published
Products (2)
FrontAccounting/FrontAccounting < 2.4.20
FrontAccounting/FrontAccounting 894adaf71393e0ef6a04fe6036fcd2464050f590
Published Jun 29, 2026
Tracked Since Jun 29, 2026