CVE-2018-17408: Zahiraccounting Zahir Enterprise Plus

High severity, CVSS 7.8. EPSS: 19% chance of exploitation in the next 30 days.

Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via a crafted CSV file that is accessed through the Import CSV File menu.

Affected products

Published 2018-10-03. Last modified 2026-06-17.