CVE-2021-36800: Akaunting OS Command Injection in 'Money.php'
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{companyid}/sales/invoices/{invoiceid} with an items[0][price] that includes a PHP callable function is executed directly. This issue was fixed in version 2.1.13 of the product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36800?
CVE-2021-36800 has been classified as a high severity vulnerability due to its potential for code injection.
How do I fix CVE-2021-36800?
To fix CVE-2021-36800, upgrade your Akaunting installation to version 2.1.13 or later.
What types of attacks can CVE-2021-36800 enable?
CVE-2021-36800 can enable attackers to execute arbitrary PHP code on the server, leading to potential complete system compromise.
Which versions of Akaunting are affected by CVE-2021-36800?
Akaunting versions 2.1.12 and earlier are affected by CVE-2021-36800.
Is there a workaround for CVE-2021-36800?
There is no official workaround for CVE-2021-36800; upgrading to the latest version is strongly recommended.