Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Company Name input field.
| Software | From | Fixed in |
|---|---|---|
| akaunting / akaunting | 1.0.0 | 1.3.17.x |