Signal is active with 1 mentions in latest observed window
Immediate actions
Patch icz matcha_invoice systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.
CVE-2026-33273 Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created… https://www.cve.org/CVERecord?id=CVE-2026-33273
Post summary
The tweet discloses a file upload vulnerability in MATCHA INVOICE 2.6.6 and earlier, noting potential for arbitrary file creation.
CVE-2026-33273
Unrestricted File Upload Vulnerability in MATCHA INVOICE 2.6.6 and Earlier
https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33273
Post summary
The statement delivers a standard disclosure of CVE‑2026‑33273, outlining an unrestricted file‑upload flaw in MATCHA INVOICE versions prior to 2.6.6, without providing exploitation details, patches, or PoC information.
⚠️ **Vulnerability Alert:** Multiple vulnerabilities in 抹茶シリーズ (SQL Injection, XSS, Insecure File Upload)
📅 **Timeline:** Disclosure: Not Available, Patch: Not Available
🆔 **CVE-2026-24913** | 📊 CVSS: 8.8 (High 🟠) | 📈 EPSS: Not Available%
🆔 **CVE-2026-27787** | 📊 CVSS: 8.8 (High 🟠) | 📈 EPSS: Not Available%
🆔 **CVE-2026-33273** | 📊 CVSS: 8.8 (High 🟠) | 📈 EPSS: Not Available%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** 抹茶請求書 2.6.6 およびそれ以前, 抹茶SNS 1.3.9 およびそれ以前
🫨 **Attack Vectors:**
- SQL Injection (authenticated)
- Stored Cross-Site Scripting (XSS)
- Insecure file upload allowing arbitrary file creation leading to potential code execution
📝 **Summary:**
Multiple high-severity vulnerabilities in the 抹茶シリーズ allow authenticated SQL injection, stored XSS, and insecure file uploads that can lead to database compromise, session theft/phishing, and server-side arbitrary file creation with potential RCE. No vendor patches are available yet, so immediate mitigation, monitoring, and preparation for patch deployment are required.
📈 **Impact Scope:** Potential unauthorized database access/modification, script execution in site visitors' browsers (session/cookie theft, phishing), and arbitrary file creation on server possibly leading to remote code execution and full server compromise.
🛡️ **Recommended Actions:**
- Apply vendor-supplied fixes/updates as soon as available
- Harden authentication and enforce least privilege for admin accounts
- Validate/sanitize inputs and use parameterized queries; encode outputs to mitigate XSS
- Enforce strict file upload validation, scan content, and store uploads outside the web root
- Deploy or tune WAF rules and increase log monitoring for IOCs
- Rotate credentials and ensure recent backups & an incident response plan
🪢 **Related Resources:**
- https://jvn.jp/jp/JVN33581068/
- https://jvndb.jvn.jp/jvndb/JVNDB-2026-000052
🏷 **Tags:** #Cybersecurity#WebApp#SQLi_XSS
Post summary
The alert announces three high‑severity CVEs affecting the 抹茶シリーズ, detailing SQLi, XSS, and insecure file upload flaws, and advises mitigations pending vendor patches.