CVE-2020-22390: High severity akaunting vulnerability
Published Jun 21, 2021
·Updated
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
Affected Software
1 affected component
Akaunting Akaunting<=2.0.9
Event History
Jun 21, 2021
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22390?
CVE-2020-22390 is classified as a high-severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2020-22390?
To fix CVE-2020-22390, upgrade Akaunting to version 2.1.0 or later.
3
What types of attacks are possible due to CVE-2020-22390?
CVE-2020-22390 allows attackers to execute arbitrary code by injecting malicious payloads into the Item name field.
4
In which versions of Akaunting is CVE-2020-22390 present?
CVE-2020-22390 affects Akaunting versions 2.0.9 and earlier.
5
What impact can CVE-2020-22390 have on users?
Users opening a compromised CSV file may unknowingly execute malicious code, leading to potential data breaches or system compromise.