Description
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Remediation
References
Related Vulnerabilities
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3167)
phpMyAdmin Other Vulnerability (CVE-2007-1325)
Sqlite Use After Free Vulnerability (CVE-2020-13871)
PHP Other Vulnerability (CVE-2005-0524)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1559)