PT-2023-28198 · Unknown · Dolibarr Erp/Crm

Chocologicall

+1

·

Published

2023-11-01

·

Updated

2025-04-03

·

CVE-2023-4197

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr ERP CRM versions <= 18.0.1
Description The issue is related to improper input validation, which fails to strip certain PHP code from user-supplied input when creating a Website. This allows an attacker to inject and evaluate arbitrary PHP code. Approximately 13,472 devices are potentially affected, mainly distributed in France, the United States, and other countries.
Recommendations For Dolibarr ERP CRM versions <= 18.0.1, update to a version higher than 18.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the Website creation feature to minimize the risk of exploitation. Avoid using user-supplied input in the creation of Websites until the issue is resolved.

Fix

Special Elements Injection

RCE

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2023-4197
CVE-2023-4197
GHSA-R9CM-PW9J-3FPX

Affected Products

Dolibarr Erp/Crm