Junglewise Threat Intelligence

CVE-2024-13071: Akinsoft e-Mutabakat Cross-Site Scripting

CVE-2024-13071 · Severity: medium · CVSS 4.3 · Published 2025-09-04

Vendors: AKINSOFT.

Executive brief

Akinsoft e-Mutabakat, a software solution used for financial reconciliation and statement matching, contains a security vulnerability that could allow an attacker to execute malicious scripts in a user's browser. If exploited, this could lead to unauthorized actions being performed on behalf of a legitimate user or the theft of sensitive session information. The risk is primarily to the integrity of the user's session and the confidentiality of data viewed within the application.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Akinsoft e-Mutabakat versions 2.02.05 through 2.02.06. The flaw stems from CWE-79, where the application fails to properly neutralize user-supplied input before including it in generated web pages. An attacker with high privileges can exploit this over the network, though it requires a victim to interact with a malicious link or page (User Interaction: Required). Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The issue is addressed in version 2.02.06.

Affected products

  • Akinsoft e-Mutabakat from 2.02.05 before v2.02.06

Timeline

  • 2025-09-04: disclosed
  • 2025-09-04: advisory

References

Related threats