Akaunting是Akaunting公司的一个应用软件提供一个在线管理资金所需的所有工具。 Akaunting 2.1.12及之前版本存在授权问题漏洞。如果攻击者知道目标的电子邮件地址,则可以通过正在运行的Akaunting实例代理密码重置请求。该问题已在2.1.13版本中修复.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-36800 | 8.7 HIGH | Akaunting OS Command Injection in 'Money.php' |
| CVE-2021-36801 | 8.1 HIGH | Akaunting Authentication Bypass in Company Selection |
| CVE-2021-36802 | 6.5 MEDIUM | Akaunting DoS via User-Controlled 'locale' Variable |
| CVE-2021-36803 | 6.3 MEDIUM | Akaunting Avatar Persistent XSS |
| CVE-2021-36805 | 5.2 MEDIUM | Akaunting Invoice Footer Persistent XSS |
No comments yet