PT-2024-36552 · Unknown · Crater Invoice

Mickaël Benassouli

+1

·

Published

2024-12-13

·

Updated

2025-07-15

·

CVE-2024-55556

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crater Invoice (affected versions not specified)
Description A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP KEY to achieve remote command execution on the server by manipulating the laravel session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector relies on an attacker obtaining Laravel's secret APP KEY, which would allow them to decrypt and manipulate session cookies containing serialized data. By altering this data and re-encrypting it with the APP KEY, the attacker could trigger arbitrary deserialization on the server, potentially leading to remote command execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-55556

Affected Products

Crater Invoice