Product
Crater Invoice versions through 6.0.6 contain a path traversal vulnerability in the self-update API that allows authenticated attackers to achieve remote code execution by uploading crafted ZIP archives.