{ "id": "CVE-2023-46865", "sourceIdentifier": "cve@mitre.org", "published": "2023-10-30T01:15:21.967", "lastModified": "2023-10-30T01:15:21.967", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image." } ], "metrics": {}, "references": [ { "url": "https://github.com/crater-invoice/crater/issues/1267", "source": "cve@mitre.org" }, { "url": "https://github.com/crater-invoice/crater/pull/1271", "source": "cve@mitre.org" } ] }