VYPR

Fa

by Frontaccounting

Source repositories

CVEs (6)

  • CVE-2019-5720CriJan 8, 2019
    risk 0.64cvss 9.8epss 0.02

    includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter.

  • CVE-2018-7176HigFeb 16, 2018
    risk 0.60cvss 8.8epss 0.02

    FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).

  • CVE-2018-1000890HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.02

    FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.

  • CVE-2026-80210MedAug 27, 2026
    risk 0.42cvss 6.5epss 0.00

    FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No…

  • CVE-2026-80211MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a user changes their own password, the…

  • CVE-2020-21244MedSep 30, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.