CVE-2024-58293: Akaunting 3.1.8 Server-Side Template Injection via Multiple Form Fields
Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58293?
CVE-2024-58293 is classified as a high severity vulnerability due to its potential for server-side template injection.
How do I fix CVE-2024-58293?
To fix CVE-2024-58293, update Akaunting to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-58293?
CVE-2024-58293 affects authenticated administrators using Akaunting version 3.1.8.
What types of fields are vulnerable in CVE-2024-58293?
CVE-2024-58293 allows injection in multiple form input fields including items, taxes, transactions, and vendor name.
What type of attack can be executed with CVE-2024-58293?
CVE-2024-58293 enables authenticated users to execute template expressions leading to arbitrary code execution.