Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
2023-05-29T21:15:09.813
2025-01-14T17:15:11.487
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dolibarr | dolibarr_erp\/crm | < 17.0.1 | Yes |