crater-invoice-inc/crater

crater-invoice-inc/crater

Releases30
Frequency4 weeks 19 hours
Last Release
Stars8.29K
Open Source Invoicing Solution for Individuals & Businesses

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

7.2 HIGH6.5 MEDIUM

Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

7.8 HIGH6.5 MEDIUM

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

6.5 MEDIUM4 MEDIUM

Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

4.3 MEDIUM4.3 MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.

5.4 MEDIUM3.5 LOW

Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.

5.3 MEDIUM5 MEDIUM

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

7.2 HIGH6 MEDIUM

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.

8.8 HIGH6.5 MEDIUM

crater is vulnerable to Unrestricted Upload of File with Dangerous Type