Loading market data...
← Back to CVE feed

CVE-2022-51019

HIGH CVSS 8.8 View on NVD ↗

Description

Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Sep 29, 2026 17:17 UTC Modified: Sep 29, 2026 21:35 UTC