CVE-2022-51019: Akaunting before 2.1.31 OS Command Injection via app alias
Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Akauntingto a version that resolves this vulnerability.Fixed in 2.1.31
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated user with access to the Akaunting admin panel can exploit it. The attacker needs to reach the module installation or update flow and control the alias parameter.
Are deployments running the default configuration affected?
The available information identifies the vulnerable module installation and update flow, but does not state whether that functionality is enabled or reachable in a default deployment. Exposure depends on whether an authenticated admin-panel user can use that flow.
What is the impact of successful exploitation?
An attacker can inject shell metacharacters through the alias parameter and execute arbitrary commands on the server. This can affect confidentiality, integrity, and availability of the affected server.
Which versions need remediation?
Akaunting versions before 2.1.31 are affected. Upgrade to version 2.1.31 or later.