CVE-2021-36802: Akaunting DoS via User-Controlled 'locale' Variable
Published Aug 4, 2021
·Updated
Akaunting version 2.1.12 and earlier suffers from a denial-of-service issue that is triggered by setting a malformed 'locale' variable and sending it in an otherwise normal HTTP POST request. This issue was fixed in version 2.1.13 of the product.
Affected Software
1 affected component
Akaunting Akaunting<=2.1.12
Event History
Aug 4, 2021
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36802.
2
What is the severity of CVE-2021-36802?
The severity of CVE-2021-36802 is medium with a severity value of 6.5.
3
How does CVE-2021-36802 affect Akaunting?
CVE-2021-36802 affects Akaunting versions 2.1.12 and earlier.
4
How can the denial-of-service issue in Akaunting be triggered?
The denial-of-service issue in Akaunting can be triggered by setting a malformed 'locale' variable and sending it in an otherwise normal HTTP POST request.
5
Has CVE-2021-36802 been fixed?
Yes, CVE-2021-36802 has been fixed in version 2.1.13 of Akaunting.