CVE-2023-30253
HIGH 8.8EPSS 82.1%
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 82.09% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2023-05-29
- Updated
- 2025-01-14
Proof-of-concept exploits (10)
- https://www.swascan.com/security-advisory-dolibarr-17-0-0/
- 04Shivam/CVE-2023-30253-Exploit0★ · 2024-05-27
- Rubikcuv5/cve-2023-302537★ · 2024-05-26
- andria-dev/DolibabyPhp1★ · 2024-07-20
- bluetoothStrawberry/CVE-2023-302530★ · 2024-09-20
- dollarboysushil/Dolibarr-17.0.0-Exploit-CVE-2023-302539★ · 2024-06-24
- g4nkd/CVE-2023-30253-PoC1★ · 2024-07-31
- nikn0laty/Exploit-for-Dolibarr-17.0.0-CVE-2023-3025341★ · 2024-05-28
- 1lkla/POC-exploit-for-Dolibarr
- Jeanback1/CVE-2023-30253-exploit