Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j57q-ff7h-j5xj

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.

Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.

EPSS

Процентиль: 19%
0.00062
Низкий

8.6 High

CVSS4

Дефекты

CWE-1336

Связанные уязвимости

nvd
около 2 месяцев назад

Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.

EPSS

Процентиль: 19%
0.00062
Низкий

8.6 High

CVSS4

Дефекты

CWE-1336