An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-08T00:00:00

Updated: 2024-08-01T22:51:11.235Z

Reserved: 2024-01-11T00:00:00

Link: CVE-2024-22836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-02-08T20:15:52.830

Modified: 2024-02-15T16:00:38.090

Link: CVE-2024-22836

cve-icon Redhat

No data.