Vulnerability record · CVE-2023-30253 · published 29 May 2023
CVE-2023-30253: Dolibarr ERP/CRM authenticated remote code execution via PHP tag case bypass
Dolibarr · Dolibarr Erp\/Crm
Dolibarr before 17.0.1 permits remote code execution by an authenticated user who injects data containing an uppercase PHP opening tag (<?PHP) that bypasses the lowercase <?php filter. Because the flaw is a filter bypass in an ERP/CRM platform, it lets a low-privileged account turn stored input into server-side code execution.
Description
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with a very high EPSS score and a public exploit reference make this a high-priority authenticated RCE, though it is not in KEV and requires a valid account.
What it is
Dolibarr before 17.0.1 permits remote code execution by an authenticated user who injects data containing an uppercase PHP opening tag (<?PHP) that bypasses the lowercase <?php filter. Because the flaw is a filter bypass in an ERP/CRM platform, it lets a low-privileged account turn stored input into server-side code execution.
Impact
An authenticated attacker gains code execution on the Dolibarr server, leading to full compromise of confidentiality, integrity and availability of the application and its data.
Attack surface
Reached over the network through the web interface; the CVSS vector shows PR:L and UI:N, so a valid low-privileged account is required but no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.82, 99.6th percentile) and a public exploit/vendor advisory reference is tagged Exploit, indicating known public exploitation techniques.
What to do
- Upgrade Dolibarr to 17.0.1 or later immediately.
- If patching is delayed, restrict access to the Dolibarr web interface to trusted networks and remove or disable unused accounts.
- Review and harden input validation and PHP tag filtering in any custom or third-party modules.
- Run Dolibarr with least privilege on the host and restrict outbound network access from the application server.
Detection
- Search web and application logs for requests containing uppercase PHP tags such as <?PHP in user-supplied fields.
- Monitor for unexpected child processes (shell, curl, wget, php) spawned by the web server user.
- Alert on new or modified files under the Dolibarr web root or upload directories.
- Correlate authenticated user activity with anomalous outbound connections from the Dolibarr host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Dolibarr/dolibarr | Product |
| https://www.swascan.com/blog/ | Vendor Advisory |
| https://www.swascan.com/security-advisory-dolibarr-17-0-0/ | ExploitVendor Advisory |
| https://github.com/Dolibarr/dolibarr | Product |
| https://www.swascan.com/blog/ | Vendor Advisory |
| https://www.swascan.com/security-advisory-dolibarr-17-0-0/ | ExploitVendor Advisory |
Track CVE-2023-30253 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-30253), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.