Lucene search

K
nvd[email protected]NVD:CVE-2023-46865
HistoryOct 30, 2023 - 1:15 a.m.

CVE-2023-46865

2023-10-3001:15:21
CWE-94
web.nvd.nist.gov
cve-2023-46865
companycontroller
image/png
idat chunk
security vulnerability
php code execution

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

42.5%

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

Affected configurations

Nvd
Node
craterappcraterRange6.0.6
VendorProductVersionCPE
craterappcrater*cpe:2.3:a:craterapp:crater:*:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

42.5%

Related for NVD:CVE-2023-46865