Executive brief
Crater Invoice is an invoicing and billing platform used by businesses to manage financial documents. A vulnerability in its automatic update mechanism allows authenticated company owners to upload malicious files that can be written to the web server directory, enabling remote code execution. An attacker with owner credentials can upload a crafted file to take complete control of the server.
Technical details
Crater Invoice's self-update API endpoints (/api/v1/update/unzip and /api/v1/update/copy) fail to sanitize user-supplied file paths and ZIP entry names before processing. The vulnerable unzip endpoint passes attacker-controlled ZIP archive paths directly to PHP's ZipArchive::extractTo() without validating entry names, allowing ZIP-Slip attacks using ../ sequences in entry names to escape the temporary extraction directory. An authenticated company owner can craft a malicious ZIP containing entries like ../../public/shell.php that extract to the web-accessible public directory, enabling arbitrary PHP file writes and remote code execution. Authentication as a company owner is required, but every Crater instance has at least one owner account. No patch is currently available for affected versions (all versions through 6.0.6, with the last release from 2022).
Affected products
- Crater Invoice through 6.0.6
Timeline
- 2026-08-25: disclosed
- 2026-07-11: other: Vulnerability discovered