CVE-2022-51019 Akaunting 模块安装更新命令注入漏洞
影响攻击者可在服务器上执行任意系统命令
AI 研判
Akaunting 2.1.31 之前版本的模块安装与更新流程存在 OS 命令注入漏洞。alias 参数未经校验即被传入 shell 命令执行,具备管理后台权限的认证用户可注入 shell 元字符执行任意命令。
影响范围
Akaunting
Akaunting 2.1.31 之前的版本。
漏洞详情
漏洞类型为 OS 命令注入,成因是模块安装/更新功能将 alias 参数直接拼接进 shell 命令且未做过滤。拥有管理面板访问权限的认证用户可在 alias 中注入 shell 元字符(如分号、管道符等),从而以 Web 服务进程权限执行任意系统命令。
利用条件与风险
利用需先获得管理后台的认证访问权限,属于需较高权限前提的高危漏洞,但一旦利用成功可完全控制服务器。
修复建议
升级至 Akaunting 2.1.31 或更高版本;临时缓解措施包括限制管理后台访问权限、对 alias 参数进行严格校验与过滤,暂无其他公开信息。
原始情报
Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.