CVE-2023-4197
CVSS V2 None
CVSS V3 None
Description
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
Overview
- CVE ID
- CVE-2023-4197
- Assigner
- STAR_Labs
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-11-01T07:58:56.679Z
- Last Modified Date
- 2023-11-01T07:58:56.679Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://starlabs.sg/advisories/23/23-4197 | third-party-advisory |
https://github.com/Dolibarr/dolibarr/commit/0ed6a63fb06be88be5a4f8bcdee83185eee4087e | patch |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-4197 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4197 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 19:17:54 | Added to TrackCVE |