MEDIUMVulnerability

CVE-2026-80210

FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates the token, including gl/gl_journal.php, gl/gl_bank.php, purchasing/supplier_invoice.php, sales/customer_invoice.php, sales/customer_payments.php and admin/company_preferences.php, so those endpoints act on POST data with no origin check. An attacker who gets an authenticated user to load a page under attacker control can auto-submit a cross-origin form to any of them and have the forged journal entry, invoice, customer payment, bank transaction or company configuration change recorded under the victim's session.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-80210
signal_observed_at
2026-09-23T22:44:39+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
published_at
2026-08-27T17:20:50.573
last_modified
2026-09-23T17:17:42.503

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Cross-Site Request Forgery (CSRF)

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-80210 — Ninja Signal Threat Intelligence | Ninja Signal