PT-2021-21369 · Akaunting · Akaunting

Trevor Christiansen

+1

·

Published

2021-08-04

·

Updated

2021-08-11

·

CVE-2021-36802

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Akaunting versions 2.1.12 and earlier
Description The issue is a denial-of-service problem triggered by setting a malformed locale variable and sending it in an otherwise normal HTTP POST request. This issue was fixed in version 2.1.13 of the product.
Recommendations For versions 2.1.12 and earlier, update to version 2.1.13 or later to resolve the issue. As a temporary workaround, consider restricting the use of the locale variable in HTTP POST requests until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36802

Affected Products

Akaunting