An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-08T00:00:00

Updated: 2024-02-08T19:23:27.475716

Reserved: 2024-01-11T00:00:00


Link: CVE-2024-22836

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-02-08T20:15:52.830

Modified: 2024-02-15T16:00:38.090


Link: CVE-2024-22836

JSON object: View

cve-icon Redhat Information

No data.

CWE