Filtered by vendor Craterapp Subscriptions
Filtered by product Crater Subscriptions
Total 9 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-46865 1 Craterapp 1 Crater 2023-11-29 7.2 High
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
CVE-2022-1032 1 Craterapp 1 Crater 2022-04-04 7.2 High
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
CVE-2022-1033 1 Craterapp 1 Crater 2022-03-28 7.8 High
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
CVE-2022-0514 1 Craterapp 1 Crater 2022-03-28 6.5 Medium
Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.
CVE-2022-0515 1 Craterapp 1 Crater 2022-03-28 4.3 Medium
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
CVE-2022-0203 1 Craterapp 1 Crater 2022-02-02 5.3 Medium
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
CVE-2022-0372 1 Craterapp 1 Crater 2022-02-02 5.4 Medium
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
CVE-2022-0242 1 Craterapp 1 Crater 2022-01-25 7.2 High
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.
CVE-2021-4080 1 Craterapp 1 Crater 2022-01-18 8.8 High
crater is vulnerable to Unrestricted Upload of File with Dangerous Type