First published: Mon May 29 2023(Updated: )
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <17.0.1 | 17.0.1 |
Dolibarr Dolibarr Erp\/crm | <17.0.1 | |
<17.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30253 is a vulnerability in Dolibarr before version 17.0.1 that allows remote code execution by an authenticated user via an uppercase manipulation.
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation, specifically by using <?PHP instead of <?php in injected data.
CVE-2023-30253 has a severity rating of 8.8 (high).
The recommended remedy for CVE-2023-30253 is to upgrade to Dolibarr version 17.0.1 or later.
You can find more information about CVE-2023-30253 on the following links: [link1], [link2], [link3].