CVE-2024-22836 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 30% (pctl 98)
Patch early
A public exploit exists.
Description
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 30.04% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2024-02-08 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| akaunting | akaunting |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Akaunting < 3.1.3 - RCE | 2024-03-10 |
References
→ the Explorer · watch your stack · NVD