CVE-2023-30253

HIGH

Dolibarr Erp/crm < 17.0.1 - OS Command Injection

Title source: rule

Description

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

Exploits (8)

nomisec WORKING POC 41 stars
by nikn0laty · poc
https://github.com/nikn0laty/Exploit-for-Dolibarr-17.0.0-CVE-2023-30253
nomisec WORKING POC 9 stars
by dollarboysushil · poc
https://github.com/dollarboysushil/Dolibarr-17.0.0-Exploit-CVE-2023-30253
nomisec WORKING POC 6 stars
by Rubikcuv5 · poc
https://github.com/Rubikcuv5/cve-2023-30253
nomisec WORKING POC 1 stars
by g4nkd · poc
https://github.com/g4nkd/CVE-2023-30253-PoC
nomisec WORKING POC 1 stars
by andria-dev · poc
https://github.com/andria-dev/DolibabyPhp
nomisec WORKING POC
by 1lkla · poc
https://github.com/1lkla/POC-exploit-for-Dolibarr
nomisec WORKING POC
by bluetoothStrawberry · poc
https://github.com/bluetoothStrawberry/CVE-2023-30253
nomisec WORKING POC
by 04Shivam · poc
https://github.com/04Shivam/CVE-2023-30253-Exploit

Scores

CVSS v3 8.8
EPSS 0.8943
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
dolibarr/dolibarr 0 - 17.0.1Packagist
dolibarr/dolibarr_erp\/crm < 17.0.1
Published May 29, 2023
Tracked Since Feb 18, 2026