← Zurück zur CVE-Suche

CVE-2026-33273

MATCHA INVOICE

Beschreibung

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.

CVSS 7.2EPSS 0.22799999999999998%Risiko 0.73
Quelle öffnen
Veröffentlicht
2026-04-08 06:16:28
Betroffene Versionen
<=2.6.6
Typ
Installed app
Zuletzt geändert
2026-07-24 23:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H