Headline
GHSA-r9cm-pw9j-3fpx: Dolibarr Improper Input Validation vulnerability
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
Dolibarr Improper Input Validation vulnerability
High severity GitHub Reviewed Published Nov 1, 2023 to the GitHub Advisory Database • Updated Nov 1, 2023
Related news
CVE-2023-4197: (CVE-2023-4197) Dolibarr ERP CRM (
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.