PT-2024-20111 · Ledgersmb+3 · Ledgersmb+3

Georgios Roumeliotis

·

Published

2024-02-02

·

Updated

2025-07-17

·

CVE-2024-23831

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LedgerSMB versions prior to 1.10.30 LedgerSMB versions prior to 1.11.9
Description LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in "/setup.pl", an attacker can trick the admin into clicking on a link which automatically submits a request to "/setup.pl" without the admin's consent. This request can be used to create a new user account with full application ("/login.pl") privileges, leading to privilege escalation.
Recommendations For versions prior to 1.10.30, update to version 1.10.30 or later. For versions prior to 1.11.9, update to version 1.11.9 or later. As a temporary workaround, consider restricting access to the "/setup.pl" endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-23831
GHSA-98FF-F638-QXJM
USN-7647-1

Affected Products

Debian
Ledgersmb
Linuxmint
Ubuntu