Stored Cross-Site Scripting Vulnerability in Akaunting by Akaunting
CVE-2020-20908
5.4MEDIUM
What is CVE-2020-20908?
A stored cross-site scripting (XSS) vulnerability exists in Akaunting version 1.3.17, allowing attackers to inject arbitrary web scripts or HTML into the application. This vulnerability is exploited through the Company Name input field, where a malicious payload can be inserted. Compromised instances may lead to unauthorized script execution in the user's browser, potentially compromising user sessions and sensitive data.
