Description
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Remediation
References
Related Vulnerabilities
Atlassian Jira Improper Authentication Vulnerability (CVE-2022-0540)
Internet Information Services Other Vulnerability (CVE-2002-1694)
Dotclear Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-1613)
Oracle Database Server CVE-2007-5512 Vulnerability (CVE-2007-5512)
MongoDb Improper Input Validation Vulnerability (CVE-2018-20804)