CVE-2024-22836: OS Command Injection
Published Feb 8, 2024
·Updated
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
Credit
u32i
Affected Software
1 affected component
Akaunting Akaunting<3.1.4
Event History
Feb 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 10, 2024
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
via ExploitDB·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-22836?
CVE-2024-22836 has a critical severity rating due to its potential for arbitrary command execution on the server.
2
How do I fix CVE-2024-22836?
To fix CVE-2024-22836, upgrade Akaunting to version 3.1.4 or later.
3
In which versions of Akaunting is CVE-2024-22836 present?
CVE-2024-22836 is present in Akaunting v3.1.3 and earlier versions.
4
What type of vulnerability is CVE-2024-22836?
CVE-2024-22836 is classified as an OS command injection vulnerability.
5
Can an attacker exploit CVE-2024-22836 remotely?
Yes, an attacker can exploit CVE-2024-22836 remotely by manipulating the company locale during the app installation process.