Executive brief
Akaunting is an online accounting software used by businesses to manage finances and reports. A security vulnerability in version 3.1.21 allows an authorized user with report-management permissions to inject malicious scripts into report descriptions. If another user views the affected report, the script could execute in their browser, potentially leading to unauthorized actions or data theft within the application.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Akaunting 3.1.21 due to improper neutralization of input in the report management workflow. An attacker with high privileges (permissions to create or update reports) can inject arbitrary HTML or JavaScript into the report description field. This payload is stored on the server and executes in the context of any user who subsequently views the compromised report. The attack requires network access and a specific user interaction (viewing the report). The vulnerability is tracked as CWE-79.
Affected products
- Akaunting Akaunting 3.1.21
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory