First published: Wed Nov 01 2023(Updated: )
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
Credit: info@starlabs.sg
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <18.0.2 | 18.0.2 |
Dolibarr ERP & CRM | <=18.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.