CVE-2021-36805: Akaunting Invoice Footer Persistent XSS
Published Aug 4, 2021
·Updated
Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.
Affected Software
1 affected component
Akaunting Akaunting<2.1.13
Event History
Aug 4, 2021
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36805?
CVE-2021-36805 is classified as a medium severity vulnerability due to its persistent cross-site scripting nature.
2
How do I fix CVE-2021-36805?
To fix CVE-2021-36805, upgrade Akaunting to version 2.1.13 or later.
3
What types of attacks can exploit CVE-2021-36805?
CVE-2021-36805 can be exploited through persistent cross-site scripting attacks targeting the sales invoice processing component.
4
Which versions of Akaunting are affected by CVE-2021-36805?
Akaunting versions 2.1.12 and earlier are affected by CVE-2021-36805.
5
Is user data at risk due to CVE-2021-36805?
Yes, CVE-2021-36805 can potentially expose user data to attackers via malicious scripts.