An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-02-08T00:00:00
Updated: 2024-08-01T22:51:11.235Z
Reserved: 2024-01-11T00:00:00
Link: CVE-2024-22836
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-02-08T20:15:52.830
Modified: 2024-11-21T08:56:41.727
Link: CVE-2024-22836
Redhat
No data.