ZeroHour

CVE-2020-22390

PoC
CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
Modified
Description

Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.

Vendors
akaunting
Products
akaunting
Weakness
CWE-1236
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.