CVE-2021-36801: Akaunting Authentication Bypass in Company Selection
Published Aug 4, 2021
·Updated
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.
Affected Software
1 affected component
Akaunting Akaunting<=2.1.12
Event History
Aug 4, 2021
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-36801?
CVE-2021-36801 is an authentication bypass issue in Akaunting version 2.1.12 and earlier, affecting the user-controllable field companies[0].
2
How severe is CVE-2021-36801?
CVE-2021-36801 has a severity rating of 8.1 (high).
3
What software versions are affected by CVE-2021-36801?
Akaunting version 2.1.12 and earlier are affected by CVE-2021-36801.
4
Has CVE-2021-36801 been fixed?
Yes, this issue was fixed in version 2.1.13 of Akaunting.