Akaunting Invoice Footer Persistent XSS
CVE-2021-36805

5.2MEDIUM

Key Information:

Vendor

Akaunting

Status
Vendor
CVE Published:
4 August 2021

What is CVE-2021-36805?

Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.

Affected Version(s)

Akaunting 2.1.12

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wiktor Sędkowski of Nokia and Trevor Christiansen of Rapid7 discovered and reported this issue through Rapid7's vulnerability disclosure program.
.