An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-08T00:00:00

Updated: 2024-08-01T22:51:11.235Z

Reserved: 2024-01-11T00:00:00

Link: CVE-2024-22836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-02-08T20:15:52.830

Modified: 2024-11-21T08:56:41.727

Link: CVE-2024-22836

cve-icon Redhat

No data.