VYPR
Medium severity5.4NVD Advisory· Published Oct 25, 2021· Updated Jun 17, 2026

CVE-2020-20908

CVE-2020-20908

Description

Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Company Name input field.

Affected products

3
  • cpe:2.3:a:akaunting:akaunting:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:akaunting:akaunting:*:*:*:*:*:*:*:*range: >=1.0.0,<=1.3.17
    • (no CPE)range: =1.3.17
  • Akaunting/Akauntingdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.