← Back to browse · API

CVE-2023-4197

Severity
HIGH
CVSS
7.5
EPSS
0.32845
Risk score
41.5
CISA KEV
No
PoC
No
Published
2023-11-01
Modified
2024-09-05
First seen
2026-08-07
Aliases
EUVD-2023-3025, GHSA-R9CM-PW9J-3FPX
Products
Dolibarr:Dolibarr ERP CRM 0 ≤18.0.1
Sources
euvd EUVD-2023-3025

Description

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

References