CVE-2023-30253: Dolibarr Erp/crm
High severity, CVSS 8.8. EPSS: 82.1% chance of exploitation in the next 30 days.
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Affected products
- Dolibarr Dolibarr Erp/crm: before 17.0.1 (fixed in 17.0.1)
Published 2023-05-29. Last modified 2026-06-17.