PT-2026-30437 · Akaunting · Akaunting
Gabriel
·
Published
2026-04-05
·
Updated
2026-04-05
·
CVE-2026-5568
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Akaunting versions up to 3.1.21
Description
Akaunting software is affected by a cross site scripting issue in the Invoice/Billing component. Manipulation of the
notes argument can lead to exploitation. The issue is potentially exploitable remotely, and the exploit has been publicly disclosed. The vendor was contacted but did not respond.Recommendations
Update Akaunting to a version later than 3.1.21.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Akaunting