crater-invoice-inc/crater

crater-invoice-inc/crater

Releases30
Frequency4 weeks 19 hours
Last Release
Stars8.32K
Open Source Invoicing Solution for Individuals & Businesses

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
3.5 LOW4 MEDIUM

A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

<= 6.0.67.2 HIGH

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

< 6.0.67.2 HIGH6.5 MEDIUM

Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

< 6.0.67.8 HIGH6.5 MEDIUM

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

< 6.0.56.5 MEDIUM4 MEDIUM

Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

< 6.0.44.3 MEDIUM4.3 MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.

< 6.0.25.4 MEDIUM3.5 LOW

Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.

< 6.0.25.3 MEDIUM5 MEDIUM

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

< 6.07.2 HIGH6 MEDIUM

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.

< 6.0.08.8 HIGH6.5 MEDIUM

crater is vulnerable to Unrestricted Upload of File with Dangerous Type