Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
{
"cwe_ids": [
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2023-05-30T20:06:23Z",
"nvd_published_at": "2023-05-29T21:15:09Z",
"severity": "HIGH"
}