CVE-2023-46865
30.10.2023, 01:15
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
Vendor | Product | Version |
---|---|---|
craterapp | crater | 𝑥 ≤ 6.0.6 |
𝑥
= Vulnerable software versions
References