Beveiligingsadvies

CVE-2026-11994

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-22 15:37:58
Laatst bijgewerkt 2026-06-22 18:26:24
Toegewezen door Fluid Attacks
CVSS-score 4.8
Status PUBLISHED

Beschrijving

Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report.