PT-2026-55854 · Crater Invoice · Crater
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
crater-invoice-inc crater versions prior to 6.0.7
Description
A weakness in the Invoice Note Handler component allows for remote cross site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue resides in the
getFormattedString() function within the app/Http/Requests/InvoicesRequest.php file. An attacker can trigger this by manipulating the notes argument.Recommendations
Update crater-invoice-inc crater to version 6.0.7 or later.
As a temporary workaround, restrict the use of the
notes argument in the Invoice Note Handler until the update is applied.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crater