FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates the token, including gl/gl_journal.php, gl/gl_bank.php, purchasing/supplier_invoice.php, sales/customer_invoice.php, sales/customer_payments.php and admin/company_preferences.php, so those endpoints act on POST data with no origin check. An attacker who gets an authenticated user to load a page under attacker control can auto-submit a cross-origin form to any of them and have the forged journal entry, invoice, customer payment, bank transaction or company configuration change recorded under the victim's session.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates the token, including gl/gl_journal.php, gl/gl_bank.php, purchasing/supplier_invoice.php, sales/customer_invoice.php, sales/customer_payments.php and admin/company_preferences.php, so those endpoints act on POST data with no origin check. An attacker who gets an authenticated user to load a page under attacker control can auto-submit a cross-origin form to any of them and have the forged journal entry, invoice, customer payment, bank transaction or company configuration change recorded under the victim's session. | |
| Title | FrontAccounting through 2.4.20 Cross-Site Request Forgery on Financial Transaction Forms | |
| First Time appeared |
Frontaccounting
Frontaccounting frontaccounting |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:frontaccounting:frontaccounting:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frontaccounting
Frontaccounting frontaccounting |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:50:31.106Z
Reserved: 2026-08-25T23:15:39.156Z
Link: CVE-2026-80210
No data.
Status : Received
Published: 2026-08-27T17:20:50.573
Modified: 2026-08-27T17:20:50.573
Link: CVE-2026-80210
No data.
OpenCVE Enrichment
No data.