Sceawere
Vulnerability Detail
CVE-2022-51019UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Akaunting OS Command Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- akaunting
- Product
- akaunting
- Attack Type
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T17:17:00.653Z",
"pubdate": "2026-09-29T17:17:00.653Z",
"executiveSummary": "Akaunting versions prior to 2.1.31 are susceptible to an OS command injection vulnerability located within the module management subsystem. This critical flaw arises from the improper neutralization of user-supplied input during the module installation and update procedures. An authenticated attacker possessing administrative access to the Akaunting management panel can manipulate the alias parameter to bypass input validation filters and inject arbitrary shell metacharacters. Successful exploitation enables the execution of malicious commands directly on the underlying host operating system with the privileges of the web server process. This vulnerability poses a severe risk, as it permits full system compromise, unauthorized data exfiltration, lateral movement within the network, and the potential deployment of persistent backdoors. Given the requirement for administrative privileges, the threat is primarily posed by malicious insiders or attackers who have successfully hijacked an administrative session, necessitating strict access controls and immediate software updates to mitigate the risk of remote code execution.",
"technicalDetails": "The vulnerability resides within the Akaunting module management functionality, specifically affecting the component responsible for processing module installations and updates. The root cause of this security flaw is an improper input validation mechanism applied to the alias parameter, which is subsequently passed to a system-level shell execution function. Because the application fails to sanitize this input or employ parameterized execution methods, it allows for the concatenation of untrusted data directly into a shell command string.\nThe exploitation flow begins with an authenticated attacker accessing the module administration interface. During the installation or update of a module, the attacker can intercept the request or provide a crafted input string within the alias parameter. By injecting shell metacharacters such as backticks (`), semicolons (;), pipes (|), or subshell syntax $(), an attacker can break out of the intended command context. For instance, an input formatted as 'module_name; [malicious_command]' would force the server to execute the legitimate module process followed immediately by the attacker's command.\nBecause the execution occurs within the context of the web server user (typically www-data or similar), the payload behavior is restricted only by the permissions assigned to that service account. Once command execution is achieved, an attacker can perform post-exploitation activities including downloading remote payloads, modifying application configuration files, accessing sensitive database credentials stored in the environment, or pivoting to other internal network services. The vulnerability effectively turns a management feature into a command-line interface for the remote user. This vector represents a high-severity security risk as it bypasses application-level security controls entirely by leveraging the operating system's command interpreter."
}