PT-2026-55854 · Crater Invoice · Crater

·

CVE-2026-14791

·

Published

2026-07-06

·

Updated

2026-07-06

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions crater-invoice-inc crater versions prior to 6.0.7
Description A weakness in the Invoice Note Handler component allows for remote cross site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue resides in the getFormattedString() function within the app/Http/Requests/InvoicesRequest.php file. An attacker can trigger this by manipulating the notes argument.
Recommendations Update crater-invoice-inc crater to version 6.0.7 or later. As a temporary workaround, restrict the use of the notes argument in the Invoice Note Handler until the update is applied.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14791

Affected Products

Crater