CVE-2026-40522
HIGHFrontAccounting < 2.4.20 SQL Injection via rep601.php
Title source: cnaDescription
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL syntax through the unparameterized WHERE clause to retrieve sensitive information including usernames, password hashes, and email addresses from the users table, rendered into PDF report output.
References (4)
Core 4
Core References
Exploit technical-description
exploit
https://jivasecurity.com/writeups/frontaccounting-sqli-bank-statement-report-cve-2026-40522
Release Notes release-notes
https://sourceforge.net/p/frontaccounting/news/2026/04/release-2420/
Patch patch
https://github.com/FrontAccountingERP/FA/commit/894adaf71393e0ef6a04fe6036fcd2464050f590
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/frontaccounting-sql-injection-via-rep601-php
Scores
CVSS v3
7.1
EPSS
0.0015
EPSS Percentile
4.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-89
CWE-916
Status
published
Products (2)
FrontAccounting/FrontAccounting
< 2.4.20
FrontAccounting/FrontAccounting
894adaf71393e0ef6a04fe6036fcd2464050f590
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026