Remote Code Execution Vulnerability in Dolibarr by Dolibarr Association
CVE-2023-30253
Key Information:
- Vendor
Dolibarr
- Status
- Vendor
- CVE Published:
- 29 May 2023
Badges
What is CVE-2023-30253?
Dolibarr versions prior to 17.0.1 are susceptible to a remote code execution vulnerability that allows authenticated users to exploit the system. This occurs through an uppercase manipulation of PHP tags, specifically by using '<?PHP' instead of '<?php' in injected data. Attackers could leverage this flaw to execute arbitrary code on the server, raising serious security concerns for users and administrators of Dolibarr.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
86% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved