Lucene search

K
cvelistMitreCVELIST:CVE-2023-46865
HistoryOct 30, 2023 - 12:00 a.m.

CVE-2023-46865

2023-10-3000:00:00
mitre
www.cve.org
1
insecure code execution
uploaded logo
companycontroller

EPSS

0.001

Percentile

42.5%

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

EPSS

0.001

Percentile

42.5%

Related for CVELIST:CVE-2023-46865