First published: Mon Jun 21 2021(Updated: )
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Akaunting Akaunting | <=2.0.9 | |
<=2.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22390 is classified as a high-severity vulnerability due to the potential for arbitrary code execution.
To fix CVE-2020-22390, upgrade Akaunting to version 2.1.0 or later.
CVE-2020-22390 allows attackers to execute arbitrary code by injecting malicious payloads into the Item name field.
CVE-2020-22390 affects Akaunting versions 2.0.9 and earlier.
Users opening a compromised CSV file may unknowingly execute malicious code, leading to potential data breaches or system compromise.