{"id":"CVE-2026-40524","summary":"FrontAccounting \u003c 2.4.20 SQL Injection via get_gl_transactions()","details":"FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without parameterization. Attackers with SA_GLANALYTIC permission can inject arbitrary SQL by supplying a closing parenthesis followed by malicious conditions to extract sensitive journal entry data through boolean-based blind SQL injection with reliable response size differentials.","modified":"2026-07-16T03:48:30.773485982Z","published":"2026-06-29T12:27:26.080Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"2.4.20"}],"source":"AFFECTED_FIELD"},{"source":"CPE_FIELD","extracted_events":[{"fixed":"2.4.20"}]},{"extracted_events":[{"fixed":"2.4.20"}],"source":"DESCRIPTION"}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40524.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40524.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40524"},{"type":"ADVISORY","url":"https://sourceforge.net/p/frontaccounting/news/2026/04/release-2420/"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/frontaccounting-sql-injection-via-get-gl-transactions"},{"type":"FIX","url":"https://github.com/FrontAccountingERP/FA/commit/647a18196caad27f96ea852e993c9e30f815357f"},{"type":"EVIDENCE","url":"https://jivasecurity.com/writeups/frontaccounting-sqli-journal-entries-report-cve-2026-40524"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frontaccountingerp/fa","events":[{"introduced":"0"},{"fixed":"647a18196caad27f96ea852e993c9e30f815357f"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40524.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"}]}