2023-10-30 03:00:37 +00:00

24 lines
723 B
JSON

{
"id": "CVE-2023-46865",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-10-30T01:15:21.967",
"lastModified": "2023-10-30T01:15:21.967",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/crater-invoice/crater/issues/1267",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/crater-invoice/crater/pull/1271",
"source": "cve@mitre.org"
}
]
}