Critical severity9.8NVD Advisory· Published Jan 8, 2019· Updated Jun 17, 2026
CVE-2019-5720
CVE-2019-5720
Description
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: =2.4.6
cpe:2.3:a:frontaccounting:frontaccounting:2.4.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:frontaccounting:frontaccounting:2.4.6:*:*:*:*:*:*:*
- (no CPE)range: <=2.4.6
Patches
Vulnerability mechanics
References
1- github.com/FrontAccountingERP/FA/issues/38nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.