Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2wq2-vmgv-993c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed directly. This issue was fixed in version 2.1.13 of the product.

Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed directly. This issue was fixed in version 2.1.13 of the product.

EPSS

Процентиль: 55%
0.00322
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.7
nvd
больше 4 лет назад

Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed directly. This issue was fixed in version 2.1.13 of the product.

CVSS3: 9.1
fstec
больше 4 лет назад

Уязвимость компонента Money.php программного обеспечения для бухгалтерского учета Akaunting, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 55%
0.00322
Низкий

Дефекты

CWE-94