Security Advisory

CVE-2026-40521

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-29 12:30:12
Last updated 2026-07-14 20:00:34
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the unique_name parameter. Attackers can supply path traversal sequences ../../../shell.php to write files outside the intended attachments directory into the web root, and by uploading PHP files without extension validation, achieve remote code execution as the web server user.