PT-2026-53270 · Unknown · Frontaccounting
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FrontAccounting versions prior to 2.4.20
Description
An issue exists in the Audit Trail report handler that allows authenticated attackers with SA GLANALYTIC permission to execute arbitrary SQL queries. This is achieved by injecting malicious code into the
PARAM 2 and PARAM 3 POST parameters. Exploitation can occur via time-based blind SQL injection using SLEEP() functions, which can be amplified across JOIN result sets to cause a denial of service by exhausting database connections. Additionally, attackers may use UNION-based injection techniques to extract arbitrary database content.Recommendations
Update to version 2.4.20 or later.
Exploit
Fix
DoS
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontaccounting