CVE-2026-40521 - FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
CVE ID :CVE-2026-40521 Published : June 29, 2026, 12:30 p.m. | 2 hours, 42 minutes ago Description :FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with...