High severity8.8NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2022-51019
CVE-2022-51019
Description
Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/akaunting/akaunting/blob/2.1.30/app/Jobs/Install/FinishUpdate.phpnvd
- github.com/akaunting/akaunting/blob/2.1.30/app/Jobs/Install/InstallModule.phpnvd
- github.com/akaunting/akaunting/commit/a1792327347a56ea575240b58673b2ece44230danvd
- github.com/akaunting/akaunting/releases/tag/2.1.31nvd
- www.vulncheck.com/advisories/akaunting-before-2.1.31-os-command-injection-via-app-aliasnvd
News mentions
0No linked articles in our index yet.