OSV 1.4.0 · unreviewed · 修改于 2026-08-25 23:32
发布时间
2026-08-25 23:32
GitHub 审查时间
—
NVD 发布时间
2026-08-25 21:19
源文件
advisories/unreviewed/2026/08/GHSA-227x-v64x-3fq7/GHSA-227x-v64x-3fq7.json
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry names passed to PHP's ZipArchive::extractTo() to write arbitrary PHP files into the web-accessible public directory and achieve remote code execution on the server.
该公告没有提供结构化的受影响软件包信息。