The LedgerSMB development team is happy to announce yet another new
version of its open source ERP and accounting application.
This release contains the fix for security vulnerability CVE-2024-23831
which allows an attacker to create a user by tricking a setup.pl admin
into clicking on a specifically crafted link. See more about this CVE
Changelog for 1.10.31
* Fix GL transaction entry regressed from 1.10.29 (#7984)
Changelog for 1.10.30
* Add missing batch and entity sequences to the Defaults screen (#7965)
* Stop warning during startup without configuration file (#7928)
* CVE-2024-23831: CSRF attack on 'setup.pl'
For installation instructions and system requirements, see
The release can be downloaded from our download site at
The release can be downloaded from GitHub at
Docker images have been published for ARMv7 (32-bit),
ARM64 (also known as ARMv8, e.g. RPi 3+) and AMD64.
These can be pulled from the GitHub Container Registry
$ docker pull ghcr.io/ledgersmb/ledgersmb:1.10.31
Or pulled from Docker Hub using the command
$ docker pull ledgersmb/ledgersmb:1.10.31
These are the sha256 checksums of the uploaded files: