Description
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
Remediation
References
Related Vulnerabilities
Atlassian Jira Deserialization of Untrusted Data Vulnerability (CVE-2020-14172)
WordPress Plugin Annonces 'abspath' Parameter Remote File Include (1.2.0.0)
WordPress Plugin WordPress Console Security Bypass (0.3.9)
MySQL CVE-2021-2170 Vulnerability (CVE-2021-2170)
ownCloud Improper Input Validation Vulnerability (CVE-2013-1939)