← Back

CVE-2024-22836

nvd nist
Published: Feb 8, 2024Modified: Jun 20, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

Affected (1)

Products: Akaunting: Akaunting
1 product
Akaunting
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.1.4

References (6)

Source: cve@mitre.org
Product
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.