Akaunting 3.1.8 Server-Side Template Injection via Multiple Form Fields
Vulnerability Description
Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58293
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- tmrswrr
References
More from Akaunting
View All →Affected Vendor
Akaunting
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.