Vulnerability Description
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craterapp | Crater | <= 6.0.6 |
Related Weaknesses (CWE)
References
- https://github.com/asylumdx/Crater-CVE-2023-46865-RCE
- https://github.com/crater-invoice/crater/issues/1267ExploitIssue TrackingVendor Advisory
- https://github.com/crater-invoice/crater/pull/1271Issue TrackingPatch
- https://notes.netbytesec.com/2023/11/post-auth-rce-in-crater-invoice.html
- https://github.com/asylumdx/Crater-CVE-2023-46865-RCE
- https://github.com/crater-invoice/crater/issues/1267ExploitIssue TrackingVendor Advisory
- https://github.com/crater-invoice/crater/pull/1271Issue TrackingPatch
- https://notes.netbytesec.com/2023/11/post-auth-rce-in-crater-invoice.html
FAQ
What is CVE-2023-46865?
CVE-2023-46865 is a vulnerability with a CVSS score of 7.2 (HIGH). /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image...
How severe is CVE-2023-46865?
CVE-2023-46865 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46865?
Check the references section above for vendor advisories and patch information. Affected products include: Craterapp Crater.