CVE-2020-22390: Akaunting
High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Akaunting <= 2.0.9 is vulnerable to CSV injection in the Item name field, export function. Attackers can inject arbitrary code into the name parameter and perform code execution when the crafted file is opened.
Affected products
- Akaunting Akaunting: up to and including 2.0.9
Published 2021-06-21. Last modified 2026-06-17.