In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection bypassing the application restrictions.Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view