HIGH
FrontAccounting
CVE published 2026-08-27
CVE-2026-80210
An attacker can exploit a Cross-Site Request Forgery (CSRF) vulnerability in FrontAccounting through 2.4.20. The application generates a CSRF token but fails to validate it in several financial transaction handlers, allowing an attacker to forge requests under an authenticated user's session. This can lead to unauthorized financial transactions or configuration changes. Defenders should prioritize verifyi [truncated]