Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9wqr-5jp4-mjmh: Dolibarr vulnerable to remote code execution via uppercase manipulation

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

ghsa
#git#php#rce#auth

Dolibarr vulnerable to remote code execution via uppercase manipulation

Moderate severity GitHub Reviewed Published May 29, 2023 to the GitHub Advisory Database • Updated May 30, 2023

Related news

CVE-2023-30253: Security Advisory: Dolibarr 17.0.0

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.