An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-01T22:51:11.235Z
Reserved: 2024-01-11T00:00:00
Link: CVE-2024-22836

No data.

Status : Modified
Published: 2024-02-08T20:15:52.830
Modified: 2024-11-21T08:56:41.727
Link: CVE-2024-22836

No data.