Dolibarr vulnerable to remote code execution via uppercase manipulation
High severity
GitHub Reviewed
Published
May 29, 2023
to the GitHub Advisory Database
•
Updated Jan 14, 2025
Description
Published by the National Vulnerability Database
May 29, 2023
Published to the GitHub Advisory Database
May 29, 2023
Reviewed
May 30, 2023
Last updated
Jan 14, 2025
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
References