CVE-2026-33273
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.7 / 10
Vector String
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Vulnerability Description
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-434
Source
NVD
Vendor
ICZ Corporation
Product
MATCHA INVOICE
Discussion (0)
Add Comment
No comments yet. Be the first!