Executive brief
Akaunting, an open-source online accounting software, is vulnerable to a security flaw where malicious code can be embedded in a user's profile name. This code is then executed when other users view invoice or bill detail pages. An attacker with high-level access could use this to perform unauthorized actions or steal information from other users viewing the document timeline.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Akaunting version 3.1.21 due to improper neutralization of input in the user profile name field. An authenticated attacker with high privileges can inject malicious HTML or JavaScript into their profile name. This payload is subsequently executed in the context of other users' browsers when they navigate to the document timeline on invoice or bill detail pages. The vulnerability is tracked as CWE-79 and requires user interaction (viewing the affected page) to trigger the execution of the stored script.
Affected products
- Akaunting Akaunting 3.1.21
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory