Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-r9cm-pw9j-3fpx: Dolibarr Improper Input Validation vulnerability

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

ghsa
#vulnerability#web#git#php

Dolibarr Improper Input Validation vulnerability

High severity GitHub Reviewed Published Nov 1, 2023 to the GitHub Advisory Database • Updated Nov 1, 2023

Related news

CVE-2023-4197: (CVE-2023-4197) Dolibarr ERP CRM (

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.