CVE-2023-30253 is an authenticated PHP code injection vulnerability in Dolibarr ERP/CRM affecting versions before 17.0.1. Based on the provided content, the flaw allows an authenticated user to inject PHP code and bypass an existing PHP tag filter by using uppercase PHP opening tags such as <?PHP instead of <?php. The vulnerable attack path is through the Website module, where injected data is processed in a way that permits execution of attacker-supplied PHP code, resulting in remote code execution on the Dolibarr server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Small standalone Python exploit repository for CVE-2023-30253 against Dolibarr ERP/CRM. The repo contains a detailed README, one main exploit script (exploit.py), and a minimal requirements file listing requests and beautifulsoup4. The exploit is not part of a larger framework. The Python script defines a DolibarrCVE202330253 class that uses requests.Session for cookie persistence and BeautifulSoup to parse HTML and extract anti-CSRF tokens. Based on the README and visible code structure, the exploit workflow is: authenticate to the Dolibarr instance, fetch CSRF tokens, create a new Website/CMS site with a random identifier, create a page, inject PHP code using a mixed/uppercase opening tag such as <?PHP to bypass the vulnerable case-sensitive filter, determine the created page identifier, and trigger the public page to execute the payload. The operator supplies target URL, Dolibarr username/password, and attacker listener host/port via CLI arguments. Primary capability is authenticated web-based RCE leading to a reverse shell as www-data. This is an operational exploit rather than a mere proof-of-concept because it automates the full attack chain and includes a working payload path, though payload customization appears limited to attacker host/port parameters. The exploit targets Dolibarr ERP/CRM 17.0.0 and, per the README, versions prior to 17.0.1 where the Website/CMS PHP-tag filter is bypassable due to case sensitivity.
This repository contains a proof-of-concept exploit for Dolibarr ERP/CRM versions 17.0.0 and below, targeting CVE-2023-30253 (PHP code injection). The exploit is implemented in Python (exploit_v2.py) and requires valid Dolibarr user credentials. It automates the process of logging in, creating a website and page, uploading a PHP reverse shell payload, and triggering it to establish a reverse shell connection to the attacker's machine. The payload is a PHP script that uses bash to connect back to the attacker's specified host and port. The README provides usage instructions and an example. The exploit interacts with several Dolibarr web endpoints and leverages the application's website management features to achieve code execution. The repository is structured with a single exploit script and a README, and is intended for demonstration and testing of the vulnerability.
This repository contains a proof-of-concept (PoC) exploit for Dolibarr ERP/CRM versions 17.0.0 and below, targeting CVE-2023-30253, a PHP code injection vulnerability. The exploit is implemented in Python (exploit.py) and requires valid Dolibarr user credentials. The script automates authentication, CSRF token retrieval, and the creation and editing of a website page within Dolibarr to inject a PHP reverse shell payload. Once the payload is triggered, the target server connects back to the attacker's specified host and port, providing a reverse shell. The README.md provides usage instructions and an example, including the need to set up a netcat listener. The exploit leverages several Dolibarr endpoints, including /index.php for authentication and /public/website/index.php for payload execution. The repository is structured simply, with one main exploit script and a README for documentation.
This repository is a proof-of-concept exploit for CVE-2023-30253, targeting Dolibarr 17.0.0 with the CMS Website plugin enabled. The exploit is implemented in Python (exploit.py) and requires the attacker to provide their own host and port for a reverse shell, as well as valid Dolibarr credentials and the target URL. The exploit works by authenticating to the Dolibarr instance, creating a new website and page, and injecting a PHP payload that opens a reverse shell to the attacker's machine. The payload is delivered via a POST request to the website management endpoints of Dolibarr. The repository includes a README with usage instructions and a requirements.txt for dependencies. The main entry point is exploit.py, which orchestrates the attack steps. The exploit is operational and provides remote code execution capabilities to an authenticated attacker.
This repository contains an exploit for CVE-2023-30253, a remote code execution vulnerability in Dolibarr ERP/CRM version 17.0.0. The exploit leverages a case manipulation bypass (using 'pHp' instead of 'php') to inject arbitrary PHP code into a website page via the Dolibarr web interface. The repository consists of a Python script ('exploit.py') and a detailed README. The script automates the exploitation process: it authenticates to the Dolibarr instance using provided credentials, creates a new website and page, injects a PHP reverse shell payload, and triggers the payload to establish a reverse shell connection to the attacker's machine. The exploit requires the attacker to have valid credentials and the target to be running a vulnerable version of Dolibarr. The main attack vector is network-based, targeting the Dolibarr web application over HTTP. Several HTTP endpoints used in the exploitation process are fingerprintable, as well as the reverse shell payload which uses '/bin/bash'. The exploit is operational, providing a working reverse shell if the target is vulnerable and properly configured.
This repository contains a Python exploit script (CVE-2023-30253.py) targeting Dolibarr ERP/CRM versions prior to 17.0.1, exploiting an authenticated remote code execution vulnerability (CVE-2023-30253). The exploit leverages a case-sensitivity issue in PHP tag parsing (accepting '<?PHP' instead of '<?php') to inject and execute arbitrary PHP code via the web interface. The script requires valid credentials and interacts with the Dolibarr web application, performing login, CSRF token extraction, and payload injection. It supports two main attack modes: executing arbitrary system commands or establishing a reverse shell to an attacker-controlled host. The endpoints '/admin/index.php' and '/website/index.php' are used for authentication and payload delivery, respectively. The repository includes a README with usage instructions and a requirements.txt for dependencies. The exploit is operational, providing real command execution and reverse shell capabilities, but is not part of a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.