← Vulnerability feed

Vulnerability record · CVE-2023-30253 · published 29 May 2023

CVE-2023-30253: Dolibarr ERP/CRM authenticated remote code execution via PHP tag case bypass

Dolibarr · Dolibarr Erp\/Crm

Dolibarr before 17.0.1 permits remote code execution by an authenticated user who injects data containing an uppercase PHP opening tag (<?PHP) that bypasses the lowercase <?php filter. Because the flaw is a filter bypass in an ERP/CRM platform, it lets a low-privileged account turn stored input into server-side code execution.

8.8 CVSS 3.1 High EPSS 82% · top 0.4% CWE-78 · OS command injection
8.8CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with a very high EPSS score and a public exploit reference make this a high-priority authenticated RCE, though it is not in KEV and requires a valid account.

What it is

Dolibarr before 17.0.1 permits remote code execution by an authenticated user who injects data containing an uppercase PHP opening tag (<?PHP) that bypasses the lowercase <?php filter. Because the flaw is a filter bypass in an ERP/CRM platform, it lets a low-privileged account turn stored input into server-side code execution.

Impact

An authenticated attacker gains code execution on the Dolibarr server, leading to full compromise of confidentiality, integrity and availability of the application and its data.

Attack surface

Reached over the network through the web interface; the CVSS vector shows PR:L and UI:N, so a valid low-privileged account is required but no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.82, 99.6th percentile) and a public exploit/vendor advisory reference is tagged Exploit, indicating known public exploitation techniques.

What to do

  • Upgrade Dolibarr to 17.0.1 or later immediately.
  • If patching is delayed, restrict access to the Dolibarr web interface to trusted networks and remove or disable unused accounts.
  • Review and harden input validation and PHP tag filtering in any custom or third-party modules.
  • Run Dolibarr with least privilege on the host and restrict outbound network access from the application server.

Detection

  • Search web and application logs for requests containing uppercase PHP tags such as <?PHP in user-supplied fields.
  • Monitor for unexpected child processes (shell, curl, wget, php) spawned by the web server user.
  • Alert on new or modified files under the Dolibarr web root or upload directories.
  • Correlate authenticated user activity with anomalous outbound connections from the Dolibarr host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-30253 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-4093Dolibarr erp\/crm sql injection vulnerabilitySQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many…EPSS 4.2%9.8CVE-2022-43138Dolibarr erp\/crm improper privilege management vulnerabilityDolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.EPSS 1.3%9.8CVE-2022-40871Dolibarr erp\/crm code injection vulnerabilityDolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if …EPSS 33%9.8CVE-2022-0224Dolibarr erp\/crm sql injection vulnerabilitydolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL CommandEPSS 2.0%9.8CVE-2021-33816Dolibarr erp\/crm code injection vulnerabilityThe website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a…EPSS 3.9%9.8CVE-2020-7995Dolibarr erp\/crm improper restriction of authentication attempts vulnerabilityThe htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.EPSS 4.5%9.8CVE-2013-2093Dolibarr erp\/crm improper input validation vulnerabilityDolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary …EPSS 5.2%9.8CVE-2013-2091Dolibarr erp\/crm sql injection vulnerabilitySQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2023-30253), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.