{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/crater-invoice--6.0.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-57863"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CVE-2026-57863\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Crater Invoice (\u003c= 6.0.6)"],"_cs_severities":["high"],"_cs_tags":["web-application","path-traversal","rce"],"_cs_type":"advisory","_cs_vendors":["Crater Invoice"],"content_html":"\u003cp\u003eCrater Invoice through version 6.0.6 is susceptible to a path traversal vulnerability within its self-update API. The vulnerability stems from improper validation of filenames within ZIP archives processed by the application's unzip endpoint. An authenticated user with 'company owner' privileges can submit a ZIP file containing entries with directory traversal sequences (such as '../').\u003c/p\u003e\n\u003cp\u003eWhen the application passes these unsanitized entries to the PHP ZipArchive::extractTo() function, it performs file operations outside of the intended extraction directory. This allows an attacker to overwrite existing files or write new files to arbitrary locations on the host filesystem. By targeting the web-accessible public directory, an attacker can upload malicious PHP scripts to achieve remote code execution (RCE). This vulnerability represents a significant risk to hosted environments where attackers may already possess low-privileged administrative access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to achieve remote code execution on the underlying server. This could lead to full system compromise, unauthorized access to sensitive financial data stored within the application, and potential lateral movement into the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Crater Invoice to a patched version beyond 6.0.6 as soon as it becomes available.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, restrict access to the self-update API or disable the module entirely if not required for standard operations.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the self-update/unzip endpoints, specifically looking for anomalous request parameters or file upload patterns.\u003c/li\u003e\n\u003cli\u003eAudit the web-accessible directories of the application for unexpected PHP files created during the update or management process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T16:16:24Z","date_published":"2026-08-25T14:08:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-crater-invoice-path-traversal/","summary":"Crater Invoice versions through 6.0.6 contain a path traversal vulnerability in the self-update API that allows authenticated attackers to achieve remote code execution by uploading crafted ZIP archives.","title":"Path Traversal in Crater Invoice Self-Update API","url":"https://feed.craftedsignal.io/briefs/2026-08-crater-invoice-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Crater Invoice (\u003c= 6.0.6)","version":"https://jsonfeed.org/version/1.1"}