crater-invoice-inc/crater
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| — | 3.5 LOW | 4 MEDIUM | ||
A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| <= 6.0.6 | 7.2 HIGH | — | ||
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image. | ||||
| < 6.0.6 | 7.2 HIGH | 6.5 MEDIUM | ||
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | ||||
| < 6.0.6 | 7.8 HIGH | 6.5 MEDIUM | ||
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. | ||||
| < 6.0.5 | 6.5 MEDIUM | 4 MEDIUM | ||
Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. | ||||
| < 6.0.4 | 4.3 MEDIUM | 4.3 MEDIUM | ||
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. | ||||
| < 6.0.2 | 5.4 MEDIUM | 3.5 LOW | ||
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. | ||||
| < 6.0.2 | 5.3 MEDIUM | 5 MEDIUM | ||
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. | ||||
| < 6.0 | 7.2 HIGH | 6 MEDIUM | ||
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. | ||||
| < 6.0.0 | 8.8 HIGH | 6.5 MEDIUM | ||
crater is vulnerable to Unrestricted Upload of File with Dangerous Type | ||||