CVE-2023-4197: Dolibarr ERP CRM (<= 18.0.1) Improper Input Sanitization Authenticated RCE
Published Nov 1, 2023
·Updated
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<18.0.2
18.0.2
dolibarr Dolibarr Erp\/crm<=18.0.1
Remediation
Event History
Nov 1, 2023
CVE Published
via MITRE·07:58 AM
Data Sourced
via MITRE·07:58 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
09:30 AM