/api/v1/company/upload-logo in CompanyController.php in...
High severity
Unreviewed
Published
Oct 30, 2023
to the GitHub Advisory Database
•
Updated Nov 29, 2023
Description
Published by the National Vulnerability Database
Oct 30, 2023
Published to the GitHub Advisory Database
Oct 30, 2023
Last updated
Nov 29, 2023
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
References