PT-2024-20111 · Ledgersmb+3 · Ledgersmb+3
Georgios Roumeliotis
·
Published
2024-02-02
·
Updated
2025-07-17
·
CVE-2024-23831
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LedgerSMB versions prior to 1.10.30
LedgerSMB versions prior to 1.11.9
Description
LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in "/setup.pl", an attacker can trick the admin into clicking on a link which automatically submits a request to "/setup.pl" without the admin's consent. This request can be used to create a new user account with full application ("/login.pl") privileges, leading to privilege escalation.
Recommendations
For versions prior to 1.10.30, update to version 1.10.30 or later.
For versions prior to 1.11.9, update to version 1.11.9 or later.
As a temporary workaround, consider restricting access to the "/setup.pl" endpoint to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Ledgersmb
Linuxmint
Ubuntu