Description
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
Remediation
References
Related Vulnerabilities
WordPress Plugin Smart Marketing SMS and Newsletters Forms Security Bypass (2.6.1)
Oracle Database Server CVE-2006-0286 Vulnerability (CVE-2006-0286)
WeBid Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-47397)
Oracle Database Server CVE-2008-0345 Vulnerability (CVE-2008-0345)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-24554)