Back to CVE List

CVE-2026-33273

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.7 / 10
Vector String
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Vulnerability Description

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
ICZ Corporation
Product
MATCHA INVOICE

External References

Discussion (0)

Add Comment

No comments yet. Be the first!