CVE-2021-36803: Akaunting Avatar Persistent XSS
Published Aug 4, 2021
·Updated
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 2.1.13 of the product.
Affected Software
1 affected component
Akaunting Akaunting<2.1.13
Event History
Aug 4, 2021
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36803?
The severity of CVE-2021-36803 is medium with a CVSS score of 5.4.
2
How can I fix the persistent cross-site scripting vulnerability in Akaunting version 2.1.12 and earlier (CVE-2021-36803)?
To fix the persistent cross-site scripting vulnerability in Akaunting version 2.1.12 and earlier (CVE-2021-36803), you should update to version 2.1.13 where the issue has been resolved.