Executive brief
Akaunting, an open-source online accounting software, is vulnerable to a security flaw in its invoicing and billing module. An attacker can inject malicious scripts into the 'notes' field of an invoice, which could then execute in the browser of another user, such as a client or staff member. This could lead to unauthorized actions being performed on behalf of the victim or the theft of session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Akaunting versions up to 3.1.21 within the Invoice/Billing component. The vulnerability is caused by improper neutralization of user-supplied input in the 'notes' argument. A remote attacker with low privileges can exploit this by injecting malicious JavaScript that executes when a victim views the affected invoice. While a proof-of-concept has been disclosed, the vendor has reportedly not responded to the disclosure, and no official patch is currently confirmed.
Affected products
- Akaunting Akaunting up to 3.1.21
Timeline
- 2026-04-05: disclosed: Exploit disclosed to the public
- 2026-04-05: advisory: Vulnerability published by VulDB/NVD