CVE-2023-30253: OS Command Injection
Published May 29, 2023
·Updated
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<17.0.1
17.0.1
dolibarr Dolibarr Erp\/crm<17.0.1
Event History
May 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
09:15 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is CVE-2023-30253?
CVE-2023-30253 is a vulnerability in Dolibarr before version 17.0.1 that allows remote code execution by an authenticated user via an uppercase manipulation.
2
How does Dolibarr before 17.0.1 allow remote code execution?
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation, specifically by using <?PHP instead of <?php in injected data.
3
What is the severity of CVE-2023-30253?
CVE-2023-30253 has a severity rating of 8.8 (high).
4
What is the recommended remedy for CVE-2023-30253?
The recommended remedy for CVE-2023-30253 is to upgrade to Dolibarr version 17.0.1 or later.
5
Where can I find more information about CVE-2023-30253?
You can find more information about CVE-2023-30253 on the following links: [link1], [link2], [link3].