CVE-2026-40522

Source
https://cve.org/CVERecord?id=CVE-2026-40522
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40522.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40522
Published
2026-06-29T12:29:40.825Z
Modified
2026-08-30T03:30:43.616427041Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
FrontAccounting < 2.4.20 SQL Injection via rep601.php
Details

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the PARAM_0 POST parameter. Attackers can supply malicious SQL syntax through the unparameterized WHERE clause to retrieve sensitive information including usernames, password hashes, and email addresses from the users table, rendered into PDF report output.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40522.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "2.4.20"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "fixed": "2.4.20"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "2.4.20"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-89",
        "CWE-916"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/frontaccountingerp/fa

Affected ranges

Type
GIT
Repo
https://github.com/frontaccountingerp/fa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40522.json"