CVE-2023-46865
HIGHcrater < 6.0.6 - Authenticated Remote Code Execution via Company Logo Image Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-46865. PoCs published by asylumdx.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2023-46865, a post-authentication RCE vulnerability in Crater Invoice <=6.0.6. The exploit bypasses file upload restrictions by embedding a PHP payload in a PNG IDAT chunk, then uploads it via the company logo feature to achieve remote code execution.
Description
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
Exploits (1)
This repository contains a functional Python exploit for CVE-2023-46865, a post-authentication RCE vulnerability in Crater Invoice <=6.0.6. The exploit bypasses file upload restrictions by embedding a PHP payload in a PNG IDAT chunk, then uploads it via the company logo feature to achieve remote code execution.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H