Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server. | |
| Title | Akaunting before 2.1.31 OS Command Injection via app alias | |
| First Time appeared |
Akaunting
Akaunting akaunting |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:akaunting:akaunting:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Akaunting
Akaunting akaunting |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T17:29:16.797Z
Reserved: 2026-09-29T15:50:38.943Z
Link: CVE-2022-51019
Updated: 2026-09-29T17:29:12.710Z
Status : Received
Published: 2026-09-29T17:17:00.653
Modified: 2026-09-29T18:17:02.587
Link: CVE-2022-51019
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')