PT-2026-31085 · Icz · Matcha Invoice
Published
2026-04-08
·
Updated
2026-04-08
·
CVE-2026-33273
CVSS v3.1
4.7
Medium
| AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matcha Invoice