Vulnerability CVE-2023-4197


Published: 2023-11-01

Description:
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

 References:
https://starlabs.sg/advisories/23/23-4197
https://github.com/Dolibarr/dolibarr/commit/0ed6a63fb06be88be5a4f8bcdee83185eee4087e

Copyright 2026, cxsecurity.com

 

Back to Top