CVE-2026-7107
published 2026-04-27CVE-2026-7107: A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This…
PriorityP343medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.20%
10.1th percentile
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | invoice_system_in_laravel | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j5xj-wjj7-2m8g: A weakness has been identified in code-projects Invoice System in Laravel 1
ghsa_unreviewed·2026-04-27
CVE-2026-7107 [MEDIUM] CWE-284 GHSA-j5xj-wjj7-2m8g: A weakness has been identified in code-projects Invoice System in Laravel 1
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
VulDB
code-projects Invoice System in Laravel 1.0 /company logo unrestricted upload
vuldb·2026-04-26·CVSS 5.3
CVE-2026-7107 [MEDIUM] code-projects Invoice System in Laravel 1.0 /company logo unrestricted upload
A vulnerability was found in code-projects Invoice System in Laravel 1.0. It has been classified as critical. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload.
This vulnerability is tracked as CVE-2026-7107. The attack is possible to be carried out remotely. Moreover, an exploit is present.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-27
Published