PT-2026-53270 · Unknown · Frontaccounting

·

CVE-2026-40523

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions FrontAccounting versions prior to 2.4.20
Description An issue exists in the Audit Trail report handler that allows authenticated attackers with SA GLANALYTIC permission to execute arbitrary SQL queries. This is achieved by injecting malicious code into the PARAM 2 and PARAM 3 POST parameters. Exploitation can occur via time-based blind SQL injection using SLEEP() functions, which can be amplified across JOIN result sets to cause a denial of service by exhausting database connections. Additionally, attackers may use UNION-based injection techniques to extract arbitrary database content.
Recommendations Update to version 2.4.20 or later.

Exploit

Fix

DoS

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40523

Affected Products

Frontaccounting