Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
https://github.com/Jeanback1/exploit-vault
https://github.com/Jeanback1/CVE-2023-30253-exploit
https://github.com/kikechans/-GodSearch
https://github.com/bluetoothStrawberry/CVE-2023-30253
https://github.com/andria-dev/DolibabyPhp